sansecio / magevulndb

List of Magento extensions with known security issues.
https://sansec.io
199 stars 32 forks source link

Add Amasty_Gdpr < 2.6.0 #85

Closed mpchadwick closed 3 years ago

mpchadwick commented 3 years ago

From the Amasty website.

" 2.6.0 - Feb 22, 2021: Improvement we improved the security of the anonymization process and downloading of customer information as well"

I reported the issue to them and characterizing the change as an "improvement" is quite the spin on things (going to refrain from going into detail publicly on what the issue actually was)

gwillem commented 3 years ago

Thanks! PS perhaps you want to share the risk level, so that people know how to prioritize this fix?

mpchadwick commented 3 years ago

It's a PII disclosure issue (no auth required).