VYPR
Medium severity5.3NVD Advisory· Published Nov 27, 2023· Updated Jun 17, 2026

CVE-2023-46355

CVE-2023-46355

Description

In the module "CSV Feeds PRO" (csvfeeds) < 2.6.1 from Bl Modules for PrestaShop, a guest can download personal information without restriction. Due to too permissive access control which does not force administrator to use password on feeds, a guest can access exports from the module which can lead to leaks of personal information from ps_customer / ps_order table such as name / surname / email / phone number / postal address.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:a:blmodules:csv_feeds_pro:*:*:*:*:*:prestashop:*:*+ 1 more
    • cpe:2.3:a:blmodules:csv_feeds_pro:*:*:*:*:*:prestashop:*:*range: <2.6.1
    • (no CPE)range: <2.6.1
  • Bl Modules for PrestaShop/CSV Feeds PROdescription

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.