mpay24- PrestaShop module vulnerability (CVE-2014-2008)

Modulempay24

Score

7.5 High

Date publish

12-09-2014

Versiones afectadas

  • Up to and including 1.5.1
  • Versions from 1.4.0 up to and including 1.4.0
  • Versions from 1.4.1 up to and including 1.4.1
  • Versions from 1.4.2 up to and including 1.4.2
  • Versions from 1.4.3 up to and including 1.4.3
  • Versions from 1.4.4 up to and including 1.4.4
  • Versions from 1.4.5 up to and including 1.4.5
  • Versions from 1.4.6 up to and including 1.4.6
  • Versions from 1.4.7 up to and including 1.4.7
  • Versions from 1.4.8 up to and including 1.4.8
  • Versions from 1.4.9 up to and including 1.4.9
  • Versions from 1.5.0 up to and including 1.5.0

Description

SQL injection vulnerability in confirm.php in the mPAY24 payment module before 1.6 for PrestaShop allows remote attackers to execute arbitrary SQL commands via the TID parameter.

References

Metrics

cvssMetricV2
sourcenvd@nist.gov
typePrimary
version2.0
vectorStringAV:N/AC:L/Au:N/C:P/I:P/A:P
baseScore7.5
accessVectorNETWORK
accessComplexityLOW
authenticationNONE
confidentialityImpactPARTIAL
integrityImpactPARTIAL
availabilityImpactPARTIAL
baseSeverityHIGH
exploitabilityScore10
impactScore6.4
acInsufInfoFalse
obtainAllPrivilegeFalse
obtainUserPrivilegeFalse
obtainOtherPrivilegeFalse
userInteractionRequiredFalse
Scroll al inicio