icommktconnector- PrestaShop module vulnerability (CVE-2019-15565)

Moduleicommktconnector

Score

9.8 Critical

Date publish

26-08-2019

Versiones afectadas

  • Less than 1.0.7

Description

The ICOMMKT connector before 1.0.7 for PrestaShop allows SQL injection in icommktconnector.php.

References

https://github.com/danidomen/icommktconn...
Patch Third Party Advisory mitre.org

Metrics

cvssMetricV30
sourcenvd@nist.gov
typePrimary
version3.0
vectorStringCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
baseScore9.8
baseSeverityCRITICAL
attackVectorNETWORK
attackComplexityLOW
privilegesRequiredNONE
userInteractionNONE
scopeUNCHANGED
confidentialityImpactHIGH
integrityImpactHIGH
availabilityImpactHIGH
exploitabilityScore3.9
impactScore5.9
cvssMetricV2
sourcenvd@nist.gov
typePrimary
version2.0
vectorStringAV:N/AC:L/Au:N/C:P/I:P/A:P
baseScore7.5
accessVectorNETWORK
accessComplexityLOW
authenticationNONE
confidentialityImpactPARTIAL
integrityImpactPARTIAL
availabilityImpactPARTIAL
baseSeverityHIGH
exploitabilityScore10
impactScore6.4
acInsufInfoFalse
obtainAllPrivilegeFalse
obtainUserPrivilegeFalse
obtainOtherPrivilegeFalse
userInteractionRequiredFalse
Scroll al inicio