PrestaShop CVE-2023-30839 vulnerability

Core

Score

9.9 Critical

Date publish

25-04-2023

Versiones afectadas

  • Less than 1.7.8.9
  • Versions from 8.0.0 up to but not including 8.0.4

Description

PrestaShop is an Open Source e-commerce web application. Versions prior to 8.0.4 and 1.7.8.9 contain a SQL filtering vulnerability. A BO user can write, update, and delete in the database, even without having specific rights. PrestaShop 8.0.4 and 1.7.8.9 contain a patch for this issue. There are no known workarounds.

References

Metrics

cvssMetricV31
sourcesecurity-advisories@github.comnvd@nist.gov
typeSecondaryPrimary
version3.13.1
vectorStringCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:HCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
baseScore9.98.8
baseSeverityCRITICALHIGH
attackVectorNETWORKNETWORK
attackComplexityLOWLOW
privilegesRequiredLOWLOW
userInteractionNONENONE
scopeCHANGEDUNCHANGED
confidentialityImpactHIGHHIGH
integrityImpactHIGHHIGH
availabilityImpactHIGHHIGH
exploitabilityScore3.12.8
impactScore65.9
Scroll al inicio