Insecure permissions in Smart Soft advancedexport before v4.4.7 allow unauthenticated attackers to arbitrarily download user information from the ps_customer table.
During installation, installed file permissions are set to allow anyone to modify those files.
Link | Tags |
---|---|
https://security.friendsofpresta.org/modules/2023/11/07/advancedexport.html | third party advisory |