ndk_advanced_custom_fields- PrestaShop module vulnerability (CVE-2022-40841)

Modulendk_advanced_custom_fields

Score

6.1 Medium

Date publish

21-12-2022

Versiones afectadas

  • Up to and including 3.5.0

Description

A cross-site scripting (XSS) vulnerability in NdkAdvancedCustomizationFields v3.5.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payloads injected into the "htmlNodes" parameter.

References

http://ndkadvancedcustomizationfields.co...
Broken Link URL Repurposed mitre.org
https://github.com/daaaalllii/cve-s/blob...
Exploit Third Party Advisory mitre.org
https://github.com/daaaalllii/cve-s/blob...
Exploit Third Party Advisory

Metrics

cvssMetricV31
sourcenvd@nist.gov134c704f-9b21-4f2e-91b3-4a467353bcc0
typePrimarySecondary
version3.13.1
vectorStringCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
baseScore6.16.1
baseSeverityMEDIUMMEDIUM
attackVectorNETWORKNETWORK
attackComplexityLOWLOW
privilegesRequiredNONENONE
userInteractionREQUIREDREQUIRED
scopeCHANGEDCHANGED
confidentialityImpactLOWLOW
integrityImpactLOWLOW
availabilityImpactNONENONE
exploitabilityScore2.82.8
impactScore2.72.7
Scroll al inicio