productcomments- PrestaShop module vulnerability (CVE-2022-35933)

Moduleproductcomments

Score

6.1 Medium

Date publish

02-09-2022

Versiones afectadas

  • Less than 5.0.2

Description

This package is a PrestaShop module that allows users to post reviews and rate products. There is a vulnerability where the attacker could steal an administrator's cookie. The issue is fixed in version 5.0.2.

References

https://github.com/PrestaShop/productcom...
Patch Third Party Advisory github.com
https://github.com/PrestaShop/productcom...
Third Party Advisory github.com

Metrics

cvssMetricV31
sourcenvd@nist.gov
typePrimary
version3.1
vectorStringCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
baseScore6.1
baseSeverityMEDIUM
attackVectorNETWORK
attackComplexityLOW
privilegesRequiredNONE
userInteractionREQUIRED
scopeCHANGED
confidentialityImpactLOW
integrityImpactLOW
availabilityImpactNONE
exploitabilityScore2.8
impactScore2.7
cvssMetricV30
sourcesecurity-advisories@github.com
typeSecondary
version3.0
vectorStringCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
baseScore4.3
baseSeverityMEDIUM
attackVectorNETWORK
attackComplexityLOW
privilegesRequiredNONE
userInteractionREQUIRED
scopeUNCHANGED
confidentialityImpactLOW
integrityImpactNONE
availabilityImpactNONE
exploitabilityScore2.8
impactScore1.4
Scroll al inicio