PrestaShop CVE-2018-19125 vulnerability

Core

Score

7.5 High

Date publish

09-11-2018

Versiones afectadas

  • Versions from 1.6.0.1 up to but not including 1.6.1.23
  • Versions from 1.7.0.0 up to but not including 1.7.4.4

Description

PrestaShop 1.6.x before 1.6.1.23 and 1.7.x before 1.7.4.4 allows remote attackers to delete an image directory.

References

http://build.prestashop.com/news/prestas...
Release Notes Third Party Advisory mitre.org
https://github.com/PrestaShop/PrestaShop...
Patch Third Party Advisory mitre.org
https://github.com/PrestaShop/PrestaShop...
Patch Third Party Advisory mitre.org
https://www.exploit-db.com/exploits/4596...
Exploit Third Party Advisory mitre.org
http://build.prestashop.com/news/prestas...
Release Notes Third Party Advisory
https://www.exploit-db.com/exploits/4596...
Exploit Third Party Advisory

Metrics

cvssMetricV30
sourcenvd@nist.gov
typePrimary
version3.0
vectorStringCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
baseScore7.5
baseSeverityHIGH
attackVectorNETWORK
attackComplexityLOW
privilegesRequiredNONE
userInteractionNONE
scopeUNCHANGED
confidentialityImpactNONE
integrityImpactHIGH
availabilityImpactNONE
exploitabilityScore3.9
impactScore3.6
cvssMetricV2
sourcenvd@nist.gov
typePrimary
version2.0
vectorStringAV:N/AC:L/Au:N/C:N/I:P/A:P
baseScore6.4
accessVectorNETWORK
accessComplexityLOW
authenticationNONE
confidentialityImpactNONE
integrityImpactPARTIAL
availabilityImpactPARTIAL
baseSeverityMEDIUM
exploitabilityScore10
impactScore4.9
acInsufInfoFalse
obtainAllPrivilegeFalse
obtainUserPrivilegeFalse
obtainOtherPrivilegeFalse
userInteractionRequiredFalse
Scroll al inicio