CVE-2023-43663

MEDIUM

PrestaShop - Privilege Escalation

Title source: llm
STIX 2.1

Description

PrestaShop is an Open Source e-commerce web application. In affected versions any module can be disabled or uninstalled from back office, even with low user right. This allows low privileged users to disable portions of a shops functionality. Commit `ce1f6708` addresses this issue and is included in version 8.1.2. Users are advised to upgrade. There are no known workarounds for this issue.

Scores

CVSS v3 6.3
EPSS 0.0010
EPSS Percentile 27.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-269
Status published
Products (2)
prestashop/prestashop < 8.1.2
prestashop/prestashop 0 - 8.1.2Packagist
Published Sep 28, 2023
Tracked Since Feb 18, 2026