Lack of data validation - Path Traversal In prestashop/prestashop
Description
PrestaShop affected by time based enumeration in FO login form
Impact
A time-based user enumeration vulnerability in the user authentication functionality of PrestaShop. This vulnerability allows an attacker to determine whether a customer account exists in the system by measuring response times.
Patches
8.2.4 and 9.0.3
Workarounds
none
References
Found by Lam Yiu Tung
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
packagist | 9.0.3, 8.2.4 |
Aliases
1. 2. 3. 4. 5.
References
1. 2. 3.