opartdevis- PrestaShop module vulnerability (CVE-2020-16194)

Moduleopartdevis

Score

5.3 Medium

Date publish

04-02-2021

Versiones afectadas

  • Less than 4.0.2

Description

An Insecure Direct Object Reference (IDOR) vulnerability was found in Prestashop Opart devis < 4.0.2. Unauthenticated attackers can have access to any user's invoice and delivery address by exploiting an IDOR on the delivery_address and invoice_address fields.

References

https://github.com/login-securite/CVE/bl...
Exploit Third Party Advisory mitre.org
https://github.com/login-securite/CVE/bl...
Exploit Third Party Advisory

Metrics

cvssMetricV31
sourcenvd@nist.gov
typePrimary
version3.1
vectorStringCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
baseScore5.3
baseSeverityMEDIUM
attackVectorNETWORK
attackComplexityLOW
privilegesRequiredNONE
userInteractionNONE
scopeUNCHANGED
confidentialityImpactLOW
integrityImpactNONE
availabilityImpactNONE
exploitabilityScore3.9
impactScore1.4
cvssMetricV2
sourcenvd@nist.gov
typePrimary
version2.0
vectorStringAV:N/AC:L/Au:N/C:P/I:N/A:N
baseScore5
accessVectorNETWORK
accessComplexityLOW
authenticationNONE
confidentialityImpactPARTIAL
integrityImpactNONE
availabilityImpactNONE
baseSeverityMEDIUM
exploitabilityScore10
impactScore2.9
acInsufInfoFalse
obtainAllPrivilegeFalse
obtainUserPrivilegeFalse
obtainOtherPrivilegeFalse
userInteractionRequiredFalse
Scroll al inicio