Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
In the module "Pixel Plus: Events + CAPI + Pixel Catalog for Facebook Module" (facebookconversiontrackingplus) up to version 2.4.9 from Smart Modules for PrestaShop, a guest can download personal information without restriction. Due to a lack of permissions control, a guest can access exports from the module which can lead to a leak of personal information from ps_customer table such as name / surname / email.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
PrestaShop 安全漏洞
Vulnerability Description
PrestaShop是美国PrestaShop公司的一套开源的电子商务解决方案。该方案提供多种支付方式、短消息提醒和商品图片缩放等功能。 PrestaShop Smart Modules for PrestaShop 2.4.9及之前版本存在安全漏洞,该漏洞源于Pixel Plus: Events + CAPI + Pixel Catalog for Facebook Module模块缺乏权限控制,导致ps_customer表中的个人信息泄露。
CVSS Information
N/A
Vulnerability Type
N/A