VYPR
High severity8.8NVD Advisory· Published Nov 7, 2023· Updated Jun 17, 2026

CVE-2023-45380

CVE-2023-45380

Description

In the module "Order Duplicator " Clone and Delete Existing Order" (orderduplicate) in version <= 1.1.7 from Silbersaiten for PrestaShop, a guest can download personal information without restriction. Due to a lack of permissions control, a guest can download personal information from ps_customer/ps_address tables such as name / surname / phone number / full postal address.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Silbersaiten/Order Duplicatordescription
  • Silbersaiten/Order Duplicatorllm-create2 versions
    <=1.1.7+ 1 more
    • (no CPE)range: <=1.1.7
    • cpe:2.3:a:silbersaiten:order_duplicator:*:*:*:*:*:prestashop:*:*range: <1.1.8

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.