From 89f9f1ea676b2ad72ccb252e9fcb5b6bca099698 Mon Sep 17 00:00:00 2001 From: TW - Vincent <315173+touchweb-vincent@users.noreply.github.com> Date: Thu, 20 Jun 2024 10:03:51 +0200 Subject: [PATCH] Update 2024-06-20-pk_themesettings.md --- _posts/2024-06-20-pk_themesettings.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/_posts/2024-06-20-pk_themesettings.md b/_posts/2024-06-20-pk_themesettings.md index 770f1ef..8a5d733 100644 --- a/_posts/2024-06-20-pk_themesettings.md +++ b/_posts/2024-06-20-pk_themesettings.md @@ -6,7 +6,7 @@ author: - TouchWeb.fr - 202-ecommerce.com meta: "CVE,PrestaShop,pk_themesettings" -severity: "medium (7.5), GDPR violation" +severity: "high (7.5), GDPR violation" --- In the module "Theme settings" (pk_themesettings) from Promokit.eu for PrestaShop, a guest can download all emails collected while SHOP is in maintenance mode. @@ -20,7 +20,7 @@ In the module "Theme settings" (pk_themesettings) from Promokit.eu for PrestaSho * **Impacted release**: <= 1.8.8 (see WARNING below) * **Product author**: Promokit.eu * **Weakness**: [CWE-359](https://cwe.mitre.org/data/definitions/359.html) -* **Severity**: medium (7.5), GDPR violation +* **Severity**: high (7.5), GDPR violation ## Description