PrestaShop CVE-2013-6358 vulnerability
Core
Score
9 CriticalDate publish
23-01-2020Versiones afectadas
- Versions from 1.5.5.0 up to and including 1.5.5.0
Description
PrestaShop 1.5.5 allows remote authenticated attackers to execute arbitrary code by uploading a crafted profile and then accessing it in the module/ directory.References
Metrics
| cvssMetricV31 | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|
| source | nvd@nist.gov | ||||||||||
| type | Primary | ||||||||||
| version | 3.1 | ||||||||||
| vectorString | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H | ||||||||||
| baseScore | 8.8 | ||||||||||
| baseSeverity | HIGH | ||||||||||
| attackVector | NETWORK | ||||||||||
| attackComplexity | LOW | ||||||||||
| privilegesRequired | LOW | ||||||||||
| userInteraction | NONE | ||||||||||
| scope | UNCHANGED | ||||||||||
| confidentialityImpact | HIGH | ||||||||||
| integrityImpact | HIGH | ||||||||||
| availabilityImpact | HIGH | ||||||||||
| exploitabilityScore | 2.8 | ||||||||||
| impactScore | 5.9 | ||||||||||
| cvssMetricV2 | |||||||||||
| source | nvd@nist.gov | ||||||||||
| type | Primary | ||||||||||
| version | 2.0 | ||||||||||
| vectorString | AV:N/AC:L/Au:S/C:C/I:C/A:C | ||||||||||
| baseScore | 9 | ||||||||||
| accessVector | NETWORK | ||||||||||
| accessComplexity | LOW | ||||||||||
| authentication | SINGLE | ||||||||||
| confidentialityImpact | COMPLETE | ||||||||||
| integrityImpact | COMPLETE | ||||||||||
| availabilityImpact | COMPLETE | ||||||||||
| baseSeverity | HIGH | ||||||||||
| exploitabilityScore | 8 | ||||||||||
| impactScore | 10 | ||||||||||
| acInsufInfo | False | ||||||||||
| obtainAllPrivilege | False | ||||||||||
| obtainUserPrivilege | False | ||||||||||
| obtainOtherPrivilege | False | ||||||||||
| userInteractionRequired | False | ||||||||||
