ndk_advanced_custom_fields- PrestaShop module vulnerability (CVE-2022-40840)

Modulendk_advanced_custom_fields

Score

6.1 Medium

Date publish

02-11-2022

Versiones afectadas

  • Up to and including 3.5.0

Description

ndk design NdkAdvancedCustomizationFields 3.5.0 is vulnerable to Cross Site Scripting (XSS) via createPdf.php.

References

http://ndkadvancedcustomizationfields.co...
Broken Link Not Applicable URL Repurposed mitre.org
https://github.com/daaaalllii/cve-s/blob...
Exploit Third Party Advisory mitre.org
http://ndkadvancedcustomizationfields.co...
Broken Link Not Applicable URL Repurposed
https://github.com/daaaalllii/cve-s/blob...
Exploit Third Party Advisory

Metrics

cvssMetricV31
sourcenvd@nist.gov134c704f-9b21-4f2e-91b3-4a467353bcc0
typePrimarySecondary
version3.13.1
vectorStringCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
baseScore6.16.1
baseSeverityMEDIUMMEDIUM
attackVectorNETWORKNETWORK
attackComplexityLOWLOW
privilegesRequiredNONENONE
userInteractionREQUIREDREQUIRED
scopeCHANGEDCHANGED
confidentialityImpactLOWLOW
integrityImpactLOWLOW
availabilityImpactNONENONE
exploitabilityScore2.82.8
impactScore2.72.7
Scroll al inicio