Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-48926


An issue in 202 ecommerce Advanced Loyalty Program: Loyalty Points before v2.3.4 for PrestaShop allows unauthenticated attackers to arbitrarily change an order status.


Published

2024-01-16T21:15:08.220

Last Modified

2025-06-02T16:15:24.727

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.3 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-862
  • Type: Secondary
    CWE-862

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application prestashop advanced_loyalty_program < 2.3.4 Yes

References