PrestaShop CVE-2023-30545 vulnerability

Core

Score

7.7 High

Date publish

25-04-2023

Versiones afectadas

  • Less than 1.7.8.9
  • Versions from 8.0.0 up to but not including 8.0.4

Description

PrestaShop is an Open Source e-commerce web application. Prior to versions 8.0.4 and 1.7.8.9, it is possible for a user with access to the SQL Manager (Advanced Options -> Database) to arbitrarily read any file on the operating system when using SQL function `LOAD_FILE` in a `SELECT` request. This gives the user access to critical information. A patch is available in PrestaShop 8.0.4 and PS 1.7.8.9

References

Metrics

cvssMetricV31
sourcesecurity-advisories@github.comnvd@nist.gov
typeSecondaryPrimary
version3.13.1
vectorStringCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:NCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
baseScore7.76.5
baseSeverityHIGHMEDIUM
attackVectorNETWORKNETWORK
attackComplexityLOWLOW
privilegesRequiredLOWLOW
userInteractionNONENONE
scopeCHANGEDUNCHANGED
confidentialityImpactHIGHHIGH
integrityImpactNONENONE
availabilityImpactNONENONE
exploitabilityScore3.12.8
impactScore43.6
Scroll al inicio