ndk_advanced_custom_fields- PrestaShop module vulnerability (CVE-2022-40842)

Modulendk_advanced_custom_fields

Score

9.1 Critical

Date publish

22-11-2022

Versiones afectadas

  • Up to and including 3.5.0

Description

ndk design NdkAdvancedCustomizationFields 3.5.0 is vulnerable to Server-side request forgery (SSRF) via rotateimg.php.

References

http://ndkadvancedcustomizationfields.co...
Broken Link Not Applicable URL Repurposed mitre.org
https://github.com/daaaalllii/cve-s/blob...
Exploit Third Party Advisory mitre.org
http://ndkadvancedcustomizationfields.co...
Broken Link Not Applicable URL Repurposed
https://github.com/daaaalllii/cve-s/blob...
Exploit Third Party Advisory

Metrics

cvssMetricV31
sourcenvd@nist.gov134c704f-9b21-4f2e-91b3-4a467353bcc0
typePrimarySecondary
version3.13.1
vectorStringCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
baseScore9.19.1
baseSeverityCRITICALCRITICAL
attackVectorNETWORKNETWORK
attackComplexityLOWLOW
privilegesRequiredNONENONE
userInteractionNONENONE
scopeUNCHANGEDUNCHANGED
confidentialityImpactHIGHHIGH
integrityImpactHIGHHIGH
availabilityImpactNONENONE
exploitabilityScore3.93.9
impactScore5.25.2
Scroll al inicio