blockwishlist- PrestaShop module vulnerability (CVE-2022-31101)

Moduleblockwishlist

Score

8.8 High

Date publish

27-06-2022

Versiones afectadas

  • Less than 2.1.1

Description

prestashop/blockwishlist is a prestashop extension which adds a block containing the customer's wishlists. In affected versions an authenticated customer can perform SQL injection. This issue is fixed in version 2.1.1. Users are advised to upgrade. There are no known workarounds for this issue.

References

http://packetstormsecurity.com/files/168...
Exploit Third Party Advisory VDB Entry github.com
https://github.com/PrestaShop/blockwishl...
Patch Third Party Advisory github.com
https://github.com/PrestaShop/blockwishl...
Third Party Advisory github.com
http://packetstormsecurity.com/files/168...
Exploit Third Party Advisory VDB Entry

Metrics

cvssMetricV31
sourcesecurity-advisories@github.comnvd@nist.gov
typeSecondaryPrimary
version3.13.1
vectorStringCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:NCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
baseScore8.18.8
baseSeverityHIGHHIGH
attackVectorNETWORKNETWORK
attackComplexityLOWLOW
privilegesRequiredLOWLOW
userInteractionNONENONE
scopeUNCHANGEDUNCHANGED
confidentialityImpactHIGHHIGH
integrityImpactHIGHHIGH
availabilityImpactNONEHIGH
exploitabilityScore2.82.8
impactScore5.25.9
cvssMetricV2
sourcenvd@nist.gov
typePrimary
version2.0
vectorStringAV:N/AC:L/Au:S/C:P/I:P/A:P
baseScore6.5
accessVectorNETWORK
accessComplexityLOW
authenticationSINGLE
confidentialityImpactPARTIAL
integrityImpactPARTIAL
availabilityImpactPARTIAL
baseSeverityMEDIUM
exploitabilityScore8
impactScore6.4
acInsufInfoFalse
obtainAllPrivilegeFalse
obtainUserPrivilegeFalse
obtainOtherPrivilegeFalse
userInteractionRequiredFalse
Scroll al inicio