
CVE-2024-33274
https://notcve.org/view.php?id=CVE-2024-33274
30 Apr 2024 — Directory Traversal vulnerability in FME Modules customfields v.2.2.7 and before allows a remote attacker to obtain sensitive information via the Custom Checkout Fields, Add Custom Fields to Checkout parameter of the ajax.php Vulnerabilidad de Directory Traversal en FME Modules customfields v.2.2.7 y anteriores permite a un atacante remoto obtener información confidencial a través de los campos de pago personalizados, agregar campos personalizados al parámetro de pago de ajax.php • https://addons.prestashop.com/en/registration-ordering-process/19008-custom-checkout-fields-add-custom-fields-to-checkout.html • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVE-2024-33271
https://notcve.org/view.php?id=CVE-2024-33271
29 Apr 2024 — An issue in FME Modules eventsmanager before 4.4.0 allows an attacker to obtain sensitive information from the ps_customer component. Un problema en FME Modules eventsmanager anterior a 4.4.0 permite a un atacante obtener información confidencial del componente ps_customer. • https://security.friendsofpresta.org/modules/2024/04/25/eventsmanager.html • CWE-359: Exposure of Private Personal Information to an Unauthorized Actor •