productcomments- PrestaShop module vulnerability (CVE-2020-26248)
Moduleproductcomments
Score
8.2 HighDate publish
03-12-2020Versiones afectadas
- Less than 4.2.1
Description
In the PrestaShop module "productcomments" before version 4.2.1, an attacker can use a Blind SQL injection to retrieve data or stop the MySQL service. The problem is fixed in 4.2.1 of the module.References
Metrics
| cvssMetricV31 | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|
| source | security-advisories@github.com | nvd@nist.gov | |||||||||
| type | Secondary | Primary | |||||||||
| version | 3.1 | 3.1 | |||||||||
| vectorString | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H | |||||||||
| baseScore | 6.8 | 8.2 | |||||||||
| baseSeverity | MEDIUM | HIGH | |||||||||
| attackVector | LOCAL | NETWORK | |||||||||
| attackComplexity | LOW | LOW | |||||||||
| privilegesRequired | NONE | NONE | |||||||||
| userInteraction | NONE | NONE | |||||||||
| scope | UNCHANGED | UNCHANGED | |||||||||
| confidentialityImpact | LOW | LOW | |||||||||
| integrityImpact | NONE | NONE | |||||||||
| availabilityImpact | HIGH | HIGH | |||||||||
| exploitabilityScore | 2.5 | 3.9 | |||||||||
| impactScore | 4.2 | 4.2 | |||||||||
| cvssMetricV2 | |||||||||||
| source | nvd@nist.gov | ||||||||||
| type | Primary | ||||||||||
| version | 2.0 | ||||||||||
| vectorString | AV:N/AC:L/Au:N/C:P/I:N/A:P | ||||||||||
| baseScore | 6.4 | ||||||||||
| accessVector | NETWORK | ||||||||||
| accessComplexity | LOW | ||||||||||
| authentication | NONE | ||||||||||
| confidentialityImpact | PARTIAL | ||||||||||
| integrityImpact | NONE | ||||||||||
| availabilityImpact | PARTIAL | ||||||||||
| baseSeverity | MEDIUM | ||||||||||
| exploitabilityScore | 10 | ||||||||||
| impactScore | 4.9 | ||||||||||
| acInsufInfo | False | ||||||||||
| obtainAllPrivilege | False | ||||||||||
| obtainUserPrivilege | False | ||||||||||
| obtainOtherPrivilege | False | ||||||||||
| userInteractionRequired | False | ||||||||||
