coingate- PrestaShop module vulnerability (CVE-2018-25104)

Modulecoingate

Score

4.3 Medium

Date publish

17-10-2024

Versiones afectadas

  • Up to and including 1.2.7

Description

A vulnerability was found in CoinGate Plugin up to 1.2.7 on PrestaShop. It has been rated as problematic. Affected by this issue is the function postProcess of the file modules/coingate/controllers/front/callback.php of the component Payment Handler. The manipulation leads to business logic errors. The attack may be launched remotely. Upgrading to version 1.2.8 is able to address this issue. The patch is identified as 0a3097db0aec7c5d66686c142c6abaa1e126ca16. It is recommended to upgrade the affected component.

References

Metrics

cvssMetricV40
sourcecna@vuldb.com
typeSecondary
version4.0
vectorStringCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
baseScore5.3
baseSeverityMEDIUM
attackVectorNETWORK
attackComplexityLOW
attackRequirementsNONE
privilegesRequiredLOW
userInteractionNONE
vulnConfidentialityImpactNONE
vulnIntegrityImpactLOW
vulnAvailabilityImpactNONE
subConfidentialityImpactNONE
subIntegrityImpactNONE
subAvailabilityImpactNONE
exploitMaturityNOT_DEFINED
confidentialityRequirementNOT_DEFINED
integrityRequirementNOT_DEFINED
availabilityRequirementNOT_DEFINED
modifiedAttackVectorNOT_DEFINED
modifiedAttackComplexityNOT_DEFINED
modifiedAttackRequirementsNOT_DEFINED
modifiedPrivilegesRequiredNOT_DEFINED
modifiedUserInteractionNOT_DEFINED
modifiedVulnConfidentialityImpactNOT_DEFINED
modifiedVulnIntegrityImpactNOT_DEFINED
modifiedVulnAvailabilityImpactNOT_DEFINED
modifiedSubConfidentialityImpactNOT_DEFINED
modifiedSubIntegrityImpactNOT_DEFINED
modifiedSubAvailabilityImpactNOT_DEFINED
SafetyNOT_DEFINED
AutomatableNOT_DEFINED
RecoveryNOT_DEFINED
valueDensityNOT_DEFINED
vulnerabilityResponseEffortNOT_DEFINED
providerUrgencyNOT_DEFINED
cvssMetricV31
sourcecna@vuldb.com
typeSecondary
version3.1
vectorStringCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
baseScore4.3
baseSeverityMEDIUM
attackVectorNETWORK
attackComplexityLOW
privilegesRequiredLOW
userInteractionNONE
scopeUNCHANGED
confidentialityImpactNONE
integrityImpactLOW
availabilityImpactNONE
exploitabilityScore2.8
impactScore1.4
cvssMetricV2
sourcecna@vuldb.com
typeSecondary
version2.0
vectorStringAV:N/AC:L/Au:S/C:N/I:P/A:N
baseScore4
accessVectorNETWORK
accessComplexityLOW
authenticationSINGLE
confidentialityImpactNONE
integrityImpactPARTIAL
availabilityImpactNONE
baseSeverityMEDIUM
exploitabilityScore8
impactScore2.9
acInsufInfoFalse
obtainAllPrivilegeFalse
obtainUserPrivilegeFalse
obtainOtherPrivilegeFalse
userInteractionRequiredFalse
Scroll al inicio