PrestaShop CVE-2022-46158 vulnerability

Core

Score

5.3 Medium

Date publish

08-12-2022

Versiones afectadas

  • Less than 1.7.8.8

Description

PrestaShop is an open-source e-commerce solution. Versions prior to 1.7.8.8 did not properly restrict host filesystem access for users. Users may have been able to view the contents of the upload directory without appropriate permissions. This issue has been addressed and users are advised to upgrade to version 1.7.8.8. There are no known workarounds for this issue.

References

https://github.com/PrestaShop/PrestaShop...
Patch Third Party Advisory github.com
https://github.com/PrestaShop/PrestaShop...
Third Party Advisory github.com

Metrics

cvssMetricV31
sourcesecurity-advisories@github.comnvd@nist.gov
typeSecondaryPrimary
version3.13.1
vectorStringCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
baseScore5.34.3
baseSeverityMEDIUMMEDIUM
attackVectorNETWORKNETWORK
attackComplexityLOWLOW
privilegesRequiredNONELOW
userInteractionNONENONE
scopeUNCHANGEDUNCHANGED
confidentialityImpactLOWLOW
integrityImpactNONENONE
availabilityImpactNONENONE
exploitabilityScore3.92.8
impactScore1.41.4
Scroll al inicio