MEDIUM5.3
GHSA-xfm3-hjcc-gv78
Any value can be changed in the configuration table by an employee having access to block reassurance module
Quick fix
GHSA-xfm3-hjcc-gv78 — prestashop/blockreassurance: upgrade to the fixed version with the command below.
composer require prestashop/blockreassurance:^5.1.4Details
### Impact An ajax function in module blockreassurance allows modifying any value in the configuration table
### Patches v5.1.4
### Workarounds no workaround available
### References
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/prestashop/blockreassurance
Introduced in:
0Fixed in: 5.1.4Fix
composer require prestashop/blockreassurance:^5.1.4References
- https://github.com/PrestaShop/blockreassurance/security/advisories/GHSA-xfm3-hjcc-gv78[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2023-47110[ADVISORY]
- https://github.com/PrestaShop/blockreassurance/commit/0a74bf1ebb907eef39e235a3a6dca0c28ed3ad23[WEB]
- https://github.com/PrestaShop/blockreassurance[PACKAGE]
- https://github.com/PrestaShop/blockreassurance/releases/tag/v5.1.4[WEB]