PrestaShop CVE-2021-21308 vulnerability

Core

Score

9.1 Critical

Date publish

26-02-2021

Versiones afectadas

  • Less than 1.7.7.2

Description

PrestaShop is a fully scalable open source e-commerce solution. In PrestaShop before version 1.7.2 the soft logout system is not complete and an attacker is able to foreign request and executes customer commands. The problem is fixed in 1.7.7.2

References

https://github.com/PrestaShop/PrestaShop...
Patch Third Party Advisory github.com
https://github.com/PrestaShop/PrestaShop...
Release Notes Third Party Advisory github.com
https://github.com/PrestaShop/PrestaShop...
Third Party Advisory github.com
https://github.com/PrestaShop/PrestaShop...
Release Notes Third Party Advisory

Metrics

cvssMetricV31
sourcesecurity-advisories@github.comnvd@nist.gov
typeSecondaryPrimary
version3.13.1
vectorStringCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
baseScore6.19.1
baseSeverityMEDIUMCRITICAL
attackVectorNETWORKNETWORK
attackComplexityLOWLOW
privilegesRequiredNONENONE
userInteractionREQUIREDNONE
scopeCHANGEDUNCHANGED
confidentialityImpactLOWHIGH
integrityImpactLOWHIGH
availabilityImpactNONENONE
exploitabilityScore2.83.9
impactScore2.75.2
cvssMetricV2
sourcenvd@nist.gov
typePrimary
version2.0
vectorStringAV:N/AC:L/Au:N/C:P/I:P/A:N
baseScore6.4
accessVectorNETWORK
accessComplexityLOW
authenticationNONE
confidentialityImpactPARTIAL
integrityImpactPARTIAL
availabilityImpactNONE
baseSeverityMEDIUM
exploitabilityScore10
impactScore4.9
acInsufInfoFalse
obtainAllPrivilegeFalse
obtainUserPrivilegeFalse
obtainOtherPrivilegeFalse
userInteractionRequiredFalse
Scroll al inicio