{"id":"GHSA-xfm3-hjcc-gv78","summary":"Any value can be changed in the configuration table by an employee having access to block reassurance module ","details":"### Impact\nAn ajax function in module blockreassurance allows modifying any value in the configuration table\n\n### Patches\nv5.1.4\n\n### Workarounds\nno workaround available\n\n### References\n","aliases":["CVE-2023-47110"],"modified":"2026-08-24T00:35:23.651512038Z","published":"2023-11-09T16:02:38Z","database_specific":{"github_reviewed_at":"2023-11-09T16:02:38Z","nvd_published_at":"2023-11-09T16:15:34Z","cwe_ids":["CWE-284"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/PrestaShop/blockreassurance/security/advisories/GHSA-xfm3-hjcc-gv78"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-47110"},{"type":"WEB","url":"https://github.com/PrestaShop/blockreassurance/commit/0a74bf1ebb907eef39e235a3a6dca0c28ed3ad23"},{"type":"PACKAGE","url":"https://github.com/PrestaShop/blockreassurance"},{"type":"WEB","url":"https://github.com/PrestaShop/blockreassurance/releases/tag/v5.1.4"}],"affected":[{"package":{"name":"prestashop/blockreassurance","ecosystem":"Packagist","purl":"pkg:composer/prestashop/blockreassurance"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.1.4"}]}],"versions":["v1.0.1","v1.0.5","v1.0.6","v2.0.0","v2.0.1","v2.0.2","v2.0.3","v3.0.0","v3.0.1","v4.1.0","v4.1.1","v5.0.0","v5.1.0","v5.1.1","v5.1.2","v5.1.3"],"database_specific":{"last_known_affected_version_range":"\u003c= 5.1.3","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/11/GHSA-xfm3-hjcc-gv78/GHSA-xfm3-hjcc-gv78.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"}]}