PrestaShop CVE-2020-4074 vulnerability

Core

Score

10 Critical

Date publish

02-07-2020

Versiones afectadas

  • Versions from 1.5.0.0 up to but not including 1.7.6.6

Description

In PrestaShop from version 1.5.0.0 and before version 1.7.6.6, the authentication system is malformed and an attacker is able to forge requests and execute admin commands. The problem is fixed in 1.7.6.6.

References

https://github.com/PrestaShop/PrestaShop...
Patch Third Party Advisory github.com
https://github.com/PrestaShop/PrestaShop...
Third Party Advisory github.com

Metrics

cvssMetricV31
sourcesecurity-advisories@github.comnvd@nist.gov
typeSecondaryPrimary
version3.13.1
vectorStringCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:LCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
baseScore8.99.8
baseSeverityHIGHCRITICAL
attackVectorNETWORKNETWORK
attackComplexityHIGHLOW
privilegesRequiredNONENONE
userInteractionNONENONE
scopeCHANGEDUNCHANGED
confidentialityImpactHIGHHIGH
integrityImpactHIGHHIGH
availabilityImpactLOWHIGH
exploitabilityScore2.23.9
impactScore65.9
cvssMetricV2
sourcenvd@nist.gov
typePrimary
version2.0
vectorStringAV:N/AC:L/Au:N/C:C/I:C/A:C
baseScore10
accessVectorNETWORK
accessComplexityLOW
authenticationNONE
confidentialityImpactCOMPLETE
integrityImpactCOMPLETE
availabilityImpactCOMPLETE
baseSeverityHIGH
exploitabilityScore10
impactScore10
acInsufInfoFalse
obtainAllPrivilegeFalse
obtainUserPrivilegeFalse
obtainOtherPrivilegeFalse
userInteractionRequiredFalse
Scroll al inicio