2 results (0.002 seconds)

CVSS: 7.5EPSS: 0%CPEs: 1EXPL: 0

30 Apr 2024 — Directory Traversal vulnerability in FME Modules customfields v.2.2.7 and before allows a remote attacker to obtain sensitive information via the Custom Checkout Fields, Add Custom Fields to Checkout parameter of the ajax.php Vulnerabilidad de Directory Traversal en FME Modules customfields v.2.2.7 y anteriores permite a un atacante remoto obtener información confidencial a través de los campos de pago personalizados, agregar campos personalizados al parámetro de pago de ajax.php • https://addons.prestashop.com/en/registration-ordering-process/19008-custom-checkout-fields-add-custom-fields-to-checkout.html • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVSS: 7.5EPSS: 0%CPEs: 1EXPL: 0

29 Apr 2024 — An issue in FME Modules eventsmanager before 4.4.0 allows an attacker to obtain sensitive information from the ps_customer component. Un problema en FME Modules eventsmanager anterior a 4.4.0 permite a un atacante obtener información confidencial del componente ps_customer. • https://security.friendsofpresta.org/modules/2024/04/25/eventsmanager.html • CWE-359: Exposure of Private Personal Information to an Unauthorized Actor •