PrestaShop CVE-2020-15080 vulnerability

Core

Score

5.3 Medium

Date publish

02-07-2020

Versiones afectadas

  • Less than 1.7.6.6

Description

In PrestaShop from version 1.7.4.0 and before version 1.7.6.6, some files should not be in the release archive, and others should not be accessible. The problem is fixed in version 1.7.6.6 A possible workaround is to make sure `composer.json` and `docker-compose.yml` are not accessible on your server.

References

https://github.com/PrestaShop/PrestaShop...
Patch Third Party Advisory github.com
https://github.com/PrestaShop/PrestaShop...
Third Party Advisory github.com

Metrics

cvssMetricV31
sourcesecurity-advisories@github.comnvd@nist.gov
typeSecondaryPrimary
version3.13.1
vectorStringCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
baseScore5.35.3
baseSeverityMEDIUMMEDIUM
attackVectorNETWORKNETWORK
attackComplexityLOWLOW
privilegesRequiredNONENONE
userInteractionNONENONE
scopeUNCHANGEDUNCHANGED
confidentialityImpactLOWLOW
integrityImpactNONENONE
availabilityImpactNONENONE
exploitabilityScore3.93.9
impactScore1.41.4
cvssMetricV2
sourcenvd@nist.gov
typePrimary
version2.0
vectorStringAV:N/AC:L/Au:N/C:P/I:N/A:N
baseScore5
accessVectorNETWORK
accessComplexityLOW
authenticationNONE
confidentialityImpactPARTIAL
integrityImpactNONE
availabilityImpactNONE
baseSeverityMEDIUM
exploitabilityScore10
impactScore2.9
acInsufInfoFalse
obtainAllPrivilegeFalse
obtainUserPrivilegeFalse
obtainOtherPrivilegeFalse
userInteractionRequiredFalse
Scroll al inicio