lgcookieslaw- PrestaShop module vulnerability (CVE-2022-44727)

Modulelgcookieslaw

Score

9.1 Critical

Date publish

10-11-2022

Versiones afectadas

  • Less than 2.1.3

Description

The EU Cookie Law GDPR (Banner + Blocker) module before 2.1.3 for PrestaShop allows SQL Injection via a cookie ( lgcookieslaw or __lglaw ).

References

https://addons.prestashop.com/en/legal/8...
Product Third Party Advisory mitre.org
https://securityandstuff.com/posts/cve-2...
Exploit Third Party Advisory mitre.org
https://www.lineagrafica.es/modp/lgcooki...
Product Vendor Advisory mitre.org
https://addons.prestashop.com/en/legal/8...
Product Third Party Advisory
https://securityandstuff.com/posts/cve-2...
Exploit Third Party Advisory

Metrics

cvssMetricV31
sourcenvd@nist.gov134c704f-9b21-4f2e-91b3-4a467353bcc0
typePrimarySecondary
version3.13.1
vectorStringCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
baseScore9.19.1
baseSeverityCRITICALCRITICAL
attackVectorNETWORKNETWORK
attackComplexityLOWLOW
privilegesRequiredNONENONE
userInteractionNONENONE
scopeUNCHANGEDUNCHANGED
confidentialityImpactHIGHHIGH
integrityImpactHIGHHIGH
availabilityImpactNONENONE
exploitabilityScore3.93.9
impactScore5.25.2
Scroll al inicio