PrestaShop CVE-2020-15082 vulnerability

Core

Score

8.8 High

Date publish

02-07-2020

Versiones afectadas

  • Versions from 1.6.0.1 up to but not including 1.7.6.6

Description

In PrestaShop from version 1.6.0.1 and before version 1.7.6.6, the dashboard allows rewriting all configuration variables. The problem is fixed in 1.7.6.6

References

https://github.com/PrestaShop/PrestaShop...
Patch Third Party Advisory github.com
https://github.com/PrestaShop/PrestaShop...
Third Party Advisory github.com

Metrics

cvssMetricV31
sourcesecurity-advisories@github.comnvd@nist.gov
typeSecondaryPrimary
version3.13.1
vectorStringCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:LCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
baseScore7.18.8
baseSeverityHIGHHIGH
attackVectorNETWORKNETWORK
attackComplexityHIGHLOW
privilegesRequiredLOWLOW
userInteractionNONENONE
scopeUNCHANGEDUNCHANGED
confidentialityImpactHIGHHIGH
integrityImpactHIGHHIGH
availabilityImpactLOWHIGH
exploitabilityScore1.62.8
impactScore5.55.9
cvssMetricV2
sourcenvd@nist.gov
typePrimary
version2.0
vectorStringAV:N/AC:L/Au:N/C:P/I:P/A:P
baseScore7.5
accessVectorNETWORK
accessComplexityLOW
authenticationNONE
confidentialityImpactPARTIAL
integrityImpactPARTIAL
availabilityImpactPARTIAL
baseSeverityHIGH
exploitabilityScore10
impactScore6.4
acInsufInfoFalse
obtainAllPrivilegeFalse
obtainUserPrivilegeFalse
obtainOtherPrivilegeFalse
userInteractionRequiredFalse
Scroll al inicio