Prestahop module King-Avis - Path traversal
Vulnerability Description
Improper Limitation of a Pathname leads to a Path Traversal vulnerability in the module King-Avis for Prestashop, allowing a user knowing the download token to read arbitrary local files.This issue affects King-Avis: before 17.3.15.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-3031
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- testeurdestylos
Affected Vendor
Webbax
View all reports →