Lack of data validation In prestashop/ps_checkout
Description
ps_checkout allows unauthorized method invocation through unvalidated parameter
Impact
Unvalidated parameter can lead to some unauthorized method invocation with very little possibilities.
Patches
The problem has been patched in versions
v5.3.0 for PrestaShop 1.7 (build number: 7.5.3.0)
v5.3.0 for PrestaShop 8 (build number: 8.5.3.0)
v5.3.0 for PrestaShop 9 (build number: 9.5.3.0)
Read the Versioning policy to learn more about the build numbers.
Credits
PrestaShop thanks PATICEO for reporting the issue.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
packagist | 5.3.0 |
Aliases
1. 2.
References
1. 2.