blog.sorcery.ie
https://blog.sorcery.ie/posts/myprestamodules_phpinfo CVE-2023-39677
HIGHNuclei
PrestaShop MyPrestaModules - PhpInfo Disclosure
Record summary
CVE-2023-39677 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.
Description
MyPrestaModules Prestashop Module v6.2.9 and UpdateProducts Prestashop Module v3.6.9 were discovered to contain a PHPInfo information disclosure vulnerability via send.php.
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 25, 2024 · Source: CVE List
Nuclei templates
1ProjectDiscoveryHIGHPrestaShop MyPrestaModules - PhpInfo DisclosureCVSS 7.5
PrestaShop modules by MyPrestaModules expose PHPInfo
Impact
An attacker can exploit this vulnerability to obtain sensitive information about the server configuration, potentially leading to further attacks.
Remediation
Apply the latest security patches and updates from the vendor to address this vulnerability.
Authorsmeme-lord
Template tagscve2023cveprestashopphpinfodisclosuresimpleimportproduct_projectvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:simpleimportproduct_project:simpleimportproduct:6.2.9:*:*:*:*:prestashop:*:*
Shodan: http.component:"PrestaShop"
Shodan: http.component:"prestashop"
https://blog.sorcery.ie/posts/myprestamodules_phpinfo/ https://cve.report/CVE-2023-39677 https://myprestamodules.com/ https://sorcery.ie/
Source: ProjectDiscovery
References
4myprestamodules.com
https://myprestamodules.com/ nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-39677 sorcery.ie
https://sorcery.ie/