PrestaShop CVE-2018-7491 vulnerability
Core
Score
7.5 HighDate publish
26-02-2018Versiones afectadas
- Up to and including 1.7.2.5
Description
In PrestaShop through 1.7.2.5, a UI-Redressing/Clickjacking vulnerability was found that might lead to state-changing impact in the context of a user or an admin, because the generateHtaccess function in classes/Tools.php sets neither X-Frame-Options nor 'Content-Security-Policy "frame-ancestors' values.References
Metrics
| cvssMetricV30 | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|
| source | nvd@nist.gov | ||||||||||
| type | Primary | ||||||||||
| version | 3.0 | ||||||||||
| vectorString | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N | ||||||||||
| baseScore | 7.5 | ||||||||||
| baseSeverity | HIGH | ||||||||||
| attackVector | NETWORK | ||||||||||
| attackComplexity | LOW | ||||||||||
| privilegesRequired | NONE | ||||||||||
| userInteraction | NONE | ||||||||||
| scope | UNCHANGED | ||||||||||
| confidentialityImpact | NONE | ||||||||||
| integrityImpact | HIGH | ||||||||||
| availabilityImpact | NONE | ||||||||||
| exploitabilityScore | 3.9 | ||||||||||
| impactScore | 3.6 | ||||||||||
| cvssMetricV2 | |||||||||||
| source | nvd@nist.gov | ||||||||||
| type | Primary | ||||||||||
| version | 2.0 | ||||||||||
| vectorString | AV:N/AC:L/Au:N/C:N/I:P/A:N | ||||||||||
| baseScore | 5 | ||||||||||
| accessVector | NETWORK | ||||||||||
| accessComplexity | LOW | ||||||||||
| authentication | NONE | ||||||||||
| confidentialityImpact | NONE | ||||||||||
| integrityImpact | PARTIAL | ||||||||||
| availabilityImpact | NONE | ||||||||||
| baseSeverity | MEDIUM | ||||||||||
| exploitabilityScore | 10 | ||||||||||
| impactScore | 2.9 | ||||||||||
| acInsufInfo | False | ||||||||||
| obtainAllPrivilege | False | ||||||||||
| obtainUserPrivilege | False | ||||||||||
| obtainOtherPrivilege | False | ||||||||||
| userInteractionRequired | False | ||||||||||
