PrestaShop CVE-2015-1175 vulnerability

Core

Score

4.3 Medium

Date publish

22-01-2015

Versiones afectadas

  • Up to and including 1.6.0.9

Description

Cross-site scripting (XSS) vulnerability in blocklayered-ajax.php in the blocklayered module in PrestaShop 1.6.0.9 and earlier allows remote attackers to inject arbitrary web script or HTML via the layered_price_slider parameter.

References

Metrics

cvssMetricV2
sourcenvd@nist.gov
typePrimary
version2.0
vectorStringAV:N/AC:M/Au:N/C:N/I:P/A:N
baseScore4.3
accessVectorNETWORK
accessComplexityMEDIUM
authenticationNONE
confidentialityImpactNONE
integrityImpactPARTIAL
availabilityImpactNONE
baseSeverityMEDIUM
exploitabilityScore8.6
impactScore2.9
acInsufInfoFalse
obtainAllPrivilegeFalse
obtainUserPrivilegeFalse
obtainOtherPrivilegeFalse
userInteractionRequiredTrue
Scroll al inicio