dashproducts- PrestaShop module vulnerability (CVE-2020-15102)

Moduledashproducts

Score

6.5 Medium

Date publish

21-07-2020

Versiones afectadas

  • Less than 2.1.0

Description

In PrestaShop Dashboard Productions before version 2.1.0, there is improper authorization which enables an attacker to change the configuration. The problem is fixed in 2.1.0.

References

https://github.com/PrestaShop/dashproduc...
Patch Third Party Advisory github.com
https://github.com/PrestaShop/dashproduc...
Third Party Advisory github.com

Metrics

cvssMetricV31
sourcesecurity-advisories@github.comnvd@nist.gov
typeSecondaryPrimary
version3.13.1
vectorStringCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:NCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
baseScore6.56.5
baseSeverityMEDIUMMEDIUM
attackVectorNETWORKNETWORK
attackComplexityLOWLOW
privilegesRequiredLOWLOW
userInteractionNONENONE
scopeUNCHANGEDUNCHANGED
confidentialityImpactNONENONE
integrityImpactHIGHHIGH
availabilityImpactNONENONE
exploitabilityScore2.82.8
impactScore3.63.6
cvssMetricV2
sourcenvd@nist.gov
typePrimary
version2.0
vectorStringAV:N/AC:L/Au:S/C:N/I:P/A:N
baseScore4
accessVectorNETWORK
accessComplexityLOW
authenticationSINGLE
confidentialityImpactNONE
integrityImpactPARTIAL
availabilityImpactNONE
baseSeverityMEDIUM
exploitabilityScore8
impactScore2.9
acInsufInfoFalse
obtainAllPrivilegeFalse
obtainUserPrivilegeFalse
obtainOtherPrivilegeFalse
userInteractionRequiredFalse
Scroll al inicio