Report an incident
Report an incident

Vulnerability in Apaczka plugin for PrestaShop
04 April 2024 | CERT Polska | #vulnerability, #warning, #cve
CVE ID CVE-2024-2759
Publication date 04 April 2024
Vendor Alsendo Sp. z o. o.
Product Apaczka (PrestaShop plugin)
Vulnerable versions through v4
Vulnerability type (CWE) Improper Access Control (CWE-284)
Report source Report to CERT Polska

Description

CERT Polska has received a report about vulnerability in Apaczka plugin for PrestaShop and participated in coordination of its disclosure.

The vulnerability CVE-2024-2759 allows information gathering (e.g. customers data) from saved templates without authentication. The vendor confirmed removing vulnerability in version v5.

Credits

We thank Jakub Przepióra for the responsible vulnerability report.


More about the coordinated vulnerability disclosure process at CERT Polska can be found at https://cert.pl/en/cvd/.