Prestashop Addon Vulnerable to CSRF - POC

Опубликовано: 02 Октябрь 2024
на канале: Astra Security
828
5

A critical CSRF (Cross-Site Request Forgery) vulnerability in PrestaShop module, Data Privacy Extended (developed by Innovadeluxe) has been found.

Plugin name: Data privacy extended (data protection law) – GDPR Module
Vulnerability name: CSRF Cross-Site Request Forgery in the “Delete Account”
Affected PrestaShop versions: v1.6.0.4 – v1.7.6.0
Vulnerable Version: versions prior to 3.7.8
Patched version: 3.7.8
Vulnerability Patched: 25th June 2019
Vulnerability Reported: 20th June 2019

For more details, click on this blog here - https://www.getastra.com/blog/911/plu...