GHSA-xfm3-hjcc-gv78
Dashboard / Vulnerabilities / GHSA-xfm3-hjcc-gv78
Summary: Any value can be changed in the configuration table by an employee having access to block reassurance module
Details: ### Impact An ajax function in module blockreassurance allows modifying any value in the configuration table ### Patches v5.1.4 ### Workarounds no workaround available ### References
References: https://github.com/PrestaShop/blockreassurance/security/advisories/GHSA-xfm3-hjcc-gv78, https://nvd.nist.gov/vuln/detail/CVE-2023-47110, https://github.com/PrestaShop/blockreassurance/commit/0a74bf1ebb907eef39e235a3a6dca0c28ed3ad23, https://github.com/PrestaShop/blockreassurance, https://github.com/PrestaShop/blockreassurance/releases/tag/v5.1.4
Affected packages
Package
Name: prestashop/blockreassurance
Purl: pkg:composer/prestashop/blockreassurance
Affected ranges
Type: ECOSYSTEM
Events:
