PrestaShop CVE-2018-19124 vulnerability

Core

Score

7.5 High

Date publish

09-11-2018

Versiones afectadas

  • Versions from 1.6.0.1 up to but not including 1.6.1.23
  • Versions from 1.7.0.0 up to but not including 1.7.4.4

Description

PrestaShop 1.6.x before 1.6.1.23 and 1.7.x before 1.7.4.4 on Windows allows remote attackers to write to arbitrary image files.

References

http://build.prestashop.com/news/prestas...
Release Notes Third Party Advisory mitre.org
https://github.com/PrestaShop/PrestaShop...
Patch Third Party Advisory mitre.org
https://github.com/PrestaShop/PrestaShop...
Patch Third Party Advisory mitre.org
http://build.prestashop.com/news/prestas...
Release Notes Third Party Advisory

Metrics

cvssMetricV30
sourcenvd@nist.gov
typePrimary
version3.0
vectorStringCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
baseScore7.5
baseSeverityHIGH
attackVectorNETWORK
attackComplexityLOW
privilegesRequiredNONE
userInteractionNONE
scopeUNCHANGED
confidentialityImpactNONE
integrityImpactHIGH
availabilityImpactNONE
exploitabilityScore3.9
impactScore3.6
cvssMetricV2
sourcenvd@nist.gov
typePrimary
version2.0
vectorStringAV:N/AC:L/Au:N/C:N/I:P/A:N
baseScore5
accessVectorNETWORK
accessComplexityLOW
authenticationNONE
confidentialityImpactNONE
integrityImpactPARTIAL
availabilityImpactNONE
baseSeverityMEDIUM
exploitabilityScore10
impactScore2.9
acInsufInfoFalse
obtainAllPrivilegeFalse
obtainUserPrivilegeFalse
obtainOtherPrivilegeFalse
userInteractionRequiredFalse
Scroll al inicio