Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-0848 | PrestaShop is an open source e-commerce web application that, prior to version 8.0.1, is vulnerable to cross-site request forgery (CSRF). When authenticating users, PrestaShop preserves session attributes. Because this does not clear CSRF tokens upon login, this might enable same-site attackers to bypass the CSRF protection mechanism by performing an attack similar to a session-fixation. The problem is fixed in version 8.0.1. |
Github GHSA |
GHSA-3g43-x7qr-96ph | Possible CSRF token fixation |
Tue, 25 Feb 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-02-25T14:58:36.483Z
Reserved: 2023-02-03T16:59:18.246Z
Link: CVE-2023-25170
Updated: 2024-08-02T11:18:35.596Z
Status : Modified
Published: 2023-03-13T17:15:12.993
Modified: 2024-11-21T07:49:14.723
Link: CVE-2023-25170
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA