Medium severity5.3NVD Advisory· Published Nov 27, 2023· Updated Jun 17, 2026
CVE-2023-46355
CVE-2023-46355
Description
In the module "CSV Feeds PRO" (csvfeeds) < 2.6.1 from Bl Modules for PrestaShop, a guest can download personal information without restriction. Due to too permissive access control which does not force administrator to use password on feeds, a guest can access exports from the module which can lead to leaks of personal information from ps_customer / ps_order table such as name / surname / email / phone number / postal address.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:blmodules:csv_feeds_pro:*:*:*:*:*:prestashop:*:*+ 1 more
- cpe:2.3:a:blmodules:csv_feeds_pro:*:*:*:*:*:prestashop:*:*range: <2.6.1
- (no CPE)range: <2.6.1
- Bl Modules for PrestaShop/CSV Feeds PROdescription
Patches
Vulnerability mechanics
References
1- security.friendsofpresta.org/modules/2023/11/23/csvfeeds.htmlnvdThird Party Advisory
News mentions
0No linked articles in our index yet.