MyPrestaModules Prestashop Module v6.2.9 and UpdateProducts Prestashop Module v3.6.9 were discovered to contain a PHPInfo information disclosure vulnerability via send.php.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://myprestamodules.com/ | product |
https://sorcery.ie | not applicable |
https://blog.sorcery.ie/posts/myprestamodules_phpinfo/ | third party advisory exploit |