opartdevis- PrestaShop module vulnerability (CVE-2020-16194)
Moduleopartdevis
Score
5.3 MediumDate publish
04-02-2021Versiones afectadas
- Less than 4.0.2
Description
An Insecure Direct Object Reference (IDOR) vulnerability was found in Prestashop Opart devis < 4.0.2. Unauthenticated attackers can have access to any user's invoice and delivery address by exploiting an IDOR on the delivery_address and invoice_address fields.References
Metrics
| cvssMetricV31 | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|
| source | nvd@nist.gov | ||||||||||
| type | Primary | ||||||||||
| version | 3.1 | ||||||||||
| vectorString | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N | ||||||||||
| baseScore | 5.3 | ||||||||||
| baseSeverity | MEDIUM | ||||||||||
| attackVector | NETWORK | ||||||||||
| attackComplexity | LOW | ||||||||||
| privilegesRequired | NONE | ||||||||||
| userInteraction | NONE | ||||||||||
| scope | UNCHANGED | ||||||||||
| confidentialityImpact | LOW | ||||||||||
| integrityImpact | NONE | ||||||||||
| availabilityImpact | NONE | ||||||||||
| exploitabilityScore | 3.9 | ||||||||||
| impactScore | 1.4 | ||||||||||
| cvssMetricV2 | |||||||||||
| source | nvd@nist.gov | ||||||||||
| type | Primary | ||||||||||
| version | 2.0 | ||||||||||
| vectorString | AV:N/AC:L/Au:N/C:P/I:N/A:N | ||||||||||
| baseScore | 5 | ||||||||||
| accessVector | NETWORK | ||||||||||
| accessComplexity | LOW | ||||||||||
| authentication | NONE | ||||||||||
| confidentialityImpact | PARTIAL | ||||||||||
| integrityImpact | NONE | ||||||||||
| availabilityImpact | NONE | ||||||||||
| baseSeverity | MEDIUM | ||||||||||
| exploitabilityScore | 10 | ||||||||||
| impactScore | 2.9 | ||||||||||
| acInsufInfo | False | ||||||||||
| obtainAllPrivilege | False | ||||||||||
| obtainUserPrivilege | False | ||||||||||
| obtainOtherPrivilege | False | ||||||||||
| userInteractionRequired | False | ||||||||||
