everpsseo- PrestaShop module vulnerability (CVE-2024-25848)

Moduleeverpsseo

Score

5.9 Medium

Date publish

08-03-2024

Versiones afectadas

  • Up to and including 8.1.2

Description

In the module "Ever Ultimate SEO" (everpsseo) <= 8.1.2 from Team Ever for PrestaShop, a guest can perform SQL injection in affected versions.

References

Metrics

cvssMetricV31
source134c704f-9b21-4f2e-91b3-4a467353bcc0
typeSecondary
version3.1
vectorStringCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
baseScore5.9
baseSeverityMEDIUM
attackVectorLOCAL
attackComplexityLOW
privilegesRequiredNONE
userInteractionNONE
scopeUNCHANGED
confidentialityImpactLOW
integrityImpactLOW
availabilityImpactLOW
exploitabilityScore2.5
impactScore3.4
Scroll al inicio