CVE-2024-41670

July 26, 2024, 3:15 p.m.

Received
CVE has been recently published to the CVE List and has been received by the NVD.

Products

PrestaShop

  • 7+ releases < 6.4.2
  • 1.6 releases < 3.18.1

Source

security-advisories@github.com

Tags

CVE-2024-41670 details

Published : July 26, 2024, 3:15 p.m.
Last Modified : July 26, 2024, 3:15 p.m.

Description

In the module "PayPal Official" for PrestaShop 7+ releases prior to version 6.4.2 and for PrestaShop 1.6 releases prior to version 3.18.1, a malicious customer can confirm an order even if payment is finally declined by PayPal. A logical weakness during the capture of a payment in case of disabled webhooks can be exploited to create an accepted order. This could allow a threat actor to confirm an order with a fraudulent payment support. Versions 6.4.2 and 3.18.1 contain a patch for the issue. Additionally, users enable webhooks and check they are callable.

CVSS Score

1 2 3 4 5 6 7.5 8 9 10

Weakness

Weakness Name Description
CWE-285 Improper Authorization The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

CVSS Data

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

Base Score

7.5

Exploitability Score

3.9

Impact Score

3.6

Base Severity

HIGH

References

URL Source
https://github.com/202ecommerce/paypal/security/advisories/GHSA-w3w3-j3mh-3354 security-advisories@github.com
This website uses the NVD API, but is not approved or certified by it.