CVE-2025-51586: PrestaShop – Information Disclosure

CVE-2025-51586: PrestaShop - Information Disclosure-渗透云记 - 专注于网络安全与技术分享
CVE-2025-51586: PrestaShop – Information Disclosure
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2025-51586: pRESTaShop – Information Disclosure

漏洞描述

User enumeration vulnerability in the AdminLogin controller in PrestaShop 1.7 through 8.2.2 allows remote attackers to obtain administrators user email addresses via manipulation of the id_employee and reset_token parameters. An attacker who has access to the Back Office login URL can trigger the password reset form to disclose the associated email address in a hidden field, even when the provided reset token is invalid. This issue has been fixed in 8.2.3.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享