CVE-2026-92810
OrtaTeknik Veri (Otomatik)
- CVSS Skoru
- 4.3
- EPSS
- —
- CWE
- CWE-639
- KEV Durumu
- Hayır
PrestaShop blockwishlist 3.0.2 sürümüne kadar getUrlByIdWishListAction yönteminde wishlist sahipliğini doğrulamada başarısız oluyor, bu da yetkili müşterilerin herhangi bir wishlistin kimlik bilgilerini kullanarak paylaşılan tokenlarını almasına olanak tanıyor. Saldırganlar sıralı wishlist kimlik bilgilerini sağlayarak geçerli paylaşımlı bağlantılar elde edebilir ve diğer müşterilerin özel wishlist içeriklerini okuyabilir.
Orijinal açıklama (İngilizce)
PrestaShop blockwishlist through 3.0.2 fails to validate wishlist ownership in the getUrlByIdWishListAction method, allowing authenticated customers to retrieve share tokens for any wishlist by identifier. Attackers can supply sequential wishlist identifiers to obtain valid share links and read other customers' private wishlist contents.
Referanslar
- https://github.com/PrestaShop/blockwishlist
- https://github.com/PrestaShop/blockwishlist/blob/v3.0.2/controllers/front/action.php#L411-L421
- https://github.com/geo-chen/oss/blob/main/prestashop.md#finding-2-blockwishlist-idor-wishlist-share-token-disclosure-via-missing-authorization-check
- https://www.vulncheck.com/advisories/prestashop-blockwishlist-through-3.0.2-information-disclosure
Bu CVE için henüz editoryal inceleme yapılmadı. Sadece otomatik teknik veri gösteriliyor.
