PrestaShop
cpe:2.3:a:prestashop:prestashop:*:*:*:*:*:*:*
- < 8.2.4
- < 9.0.3
A time-based user enumeration vulnerability has been identified in the authentication functionality of PrestaShop. This issue affects versions prior to 8.2.4 and 9.0.3. The vulnerability allows attackers to determine the existence of customer accounts by measuring response times during the login process.
Exploitation of this vulnerability could lead to unauthorized account enumeration, allowing attackers to verify the existence of user accounts.
Users can upgrade to PrestaShop versions 8.2.4 or 9.0.3 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.