productcomments- PrestaShop module vulnerability (CVE-2020-26225)

Moduleproductcomments

Score

8.7 High

Date publish

16-11-2020

Versiones afectadas

  • Versions from 4.0.0 up to but not including 4.2.0

Description

In PrestaShop Product Comments before version 4.2.0, an attacker could inject malicious web code into the users' web browsers by creating a malicious link. The problem was introduced in version 4.0.0 and is fixed in 4.2.0

References

https://github.com/PrestaShop/productcom...
Patch Third Party Advisory github.com
https://github.com/PrestaShop/productcom...
Third Party Advisory github.com

Metrics

cvssMetricV31
sourcesecurity-advisories@github.comnvd@nist.gov
typeSecondaryPrimary
version3.13.1
vectorStringCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:NCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
baseScore8.76.1
baseSeverityHIGHMEDIUM
attackVectorNETWORKNETWORK
attackComplexityLOWLOW
privilegesRequiredLOWNONE
userInteractionREQUIREDREQUIRED
scopeCHANGEDCHANGED
confidentialityImpactHIGHLOW
integrityImpactHIGHLOW
availabilityImpactNONENONE
exploitabilityScore2.32.8
impactScore5.82.7
cvssMetricV2
sourcenvd@nist.gov
typePrimary
version2.0
vectorStringAV:N/AC:M/Au:N/C:N/I:P/A:N
baseScore4.3
accessVectorNETWORK
accessComplexityMEDIUM
authenticationNONE
confidentialityImpactNONE
integrityImpactPARTIAL
availabilityImpactNONE
baseSeverityMEDIUM
exploitabilityScore8.6
impactScore2.9
acInsufInfoFalse
obtainAllPrivilegeFalse
obtainUserPrivilegeFalse
obtainOtherPrivilegeFalse
userInteractionRequiredTrue
Scroll al inicio