High severity8.8NVD Advisory· Published Nov 7, 2023· Updated Jun 17, 2026
CVE-2023-45380
CVE-2023-45380
Description
In the module "Order Duplicator " Clone and Delete Existing Order" (orderduplicate) in version <= 1.1.7 from Silbersaiten for PrestaShop, a guest can download personal information without restriction. Due to a lack of permissions control, a guest can download personal information from ps_customer/ps_address tables such as name / surname / phone number / full postal address.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Silbersaiten/Order Duplicatordescription
<=1.1.7+ 1 more
- (no CPE)range: <=1.1.7
- cpe:2.3:a:silbersaiten:order_duplicator:*:*:*:*:*:prestashop:*:*range: <1.1.8
Patches
Vulnerability mechanics
References
1- security.friendsofpresta.org/modules/2023/11/07/orderduplicate.htmlnvdThird Party Advisory
News mentions
0No linked articles in our index yet.