漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
N/A
Vulnerability Description
In the module "Product Catalog (CSV, Excel, XML) Export PRO" (exportproducts) in versions up to 4.1.1 from MyPrestaModules for PrestaShop, a guest can download personal information without restriction by performing a path traversal attack. Due to a lack of permissions control and a lack of control in the path name construction, a guest can perform a path traversal to view all files on the information system.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
PrestaShop 路径遍历漏洞
Vulnerability Description
PrestaShop是美国PrestaShop公司的一套开源的电子商务解决方案。该方案提供多种支付方式、短消息提醒和商品图片缩放等功能。 PrestaShop Product Catalog (CSV, Excel, XML) Export PRO 4.1.1及之前版本存在安全漏洞,该漏洞源于缺乏权限控制和路径名构造的控制,导致存在路径遍历漏洞。攻击者可利用该漏洞查看信息系统上的所有文件。
CVSS Information
N/A
Vulnerability Type
N/A