ndk_advanced_custom_fields- PrestaShop module vulnerability (CVE-2022-40839)

Modulendk_advanced_custom_fields

Score

7.5 High

Date publish

01-11-2022

Versiones afectadas

  • Versions from 3.5.0 up to and including 3.5.0

Description

A SQL injection vulnerability in the height and width parameter in NdkAdvancedCustomizationFields v3.5.0 allows unauthenticated attackers to exfiltrate database data.

References

http://ndk.com
Broken Link Product mitre.org
http://ndkadvancedcustomizationfields.co...
Broken Link Product URL Repurposed mitre.org
https://github.com/daaaalllii/cve-s/blob...
Exploit Third Party Advisory mitre.org
http://ndk.com
Broken Link Product
http://ndkadvancedcustomizationfields.co...
Broken Link Product URL Repurposed
https://github.com/daaaalllii/cve-s/blob...
Exploit Third Party Advisory

Metrics

cvssMetricV31
sourcenvd@nist.gov134c704f-9b21-4f2e-91b3-4a467353bcc0
typePrimarySecondary
version3.13.1
vectorStringCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
baseScore7.57.5
baseSeverityHIGHHIGH
attackVectorNETWORKNETWORK
attackComplexityLOWLOW
privilegesRequiredNONENONE
userInteractionNONENONE
scopeUNCHANGEDUNCHANGED
confidentialityImpactHIGHHIGH
integrityImpactNONENONE
availabilityImpactNONENONE
exploitabilityScore3.93.9
impactScore3.63.6
Scroll al inicio