PrestaShop CVE-2020-5293 vulnerability

Core

Score

6.5 Medium

Date publish

20-04-2020

Versiones afectadas

  • Less than 1.7.6.5

Description

In PrestaShop between versions 1.7.0.0 and 1.7.6.5, there are improper access controls on product page with combinations, attachments and specific prices. The problem is fixed in 1.7.6.5.

References

https://github.com/PrestaShop/PrestaShop...
Patch Third Party Advisory github.com
https://github.com/PrestaShop/PrestaShop...
Patch Third Party Advisory github.com

Metrics

cvssMetricV31
sourcesecurity-advisories@github.comnvd@nist.gov
typeSecondaryPrimary
version3.13.1
vectorStringCVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:L/A:NCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
baseScore6.56.5
baseSeverityMEDIUMMEDIUM
attackVectorNETWORKNETWORK
attackComplexityHIGHLOW
privilegesRequiredLOWNONE
userInteractionREQUIREDNONE
scopeCHANGEDUNCHANGED
confidentialityImpactHIGHLOW
integrityImpactLOWLOW
availabilityImpactNONENONE
exploitabilityScore1.33.9
impactScore4.72.5
cvssMetricV2
sourcenvd@nist.gov
typePrimary
version2.0
vectorStringAV:N/AC:L/Au:N/C:P/I:P/A:N
baseScore6.4
accessVectorNETWORK
accessComplexityLOW
authenticationNONE
confidentialityImpactPARTIAL
integrityImpactPARTIAL
availabilityImpactNONE
baseSeverityMEDIUM
exploitabilityScore10
impactScore4.9
acInsufInfoFalse
obtainAllPrivilegeFalse
obtainUserPrivilegeFalse
obtainOtherPrivilegeFalse
userInteractionRequiredFalse
Scroll al inicio