amazon- PrestaShop module vulnerability (CVE-2023-33777)

Moduleamazon

Score

5.3 Medium

Date publish

25-07-2023

Versiones afectadas

  • Less than 5.2.24

Description

An issue in /functions/fbaorder.php of Prestashop amazon before v5.2.24 allows attackers to execute a directory traversal attack.

References

Metrics

cvssMetricV31
sourcenvd@nist.gov
typePrimary
version3.1
vectorStringCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
baseScore5.3
baseSeverityMEDIUM
attackVectorNETWORK
attackComplexityLOW
privilegesRequiredNONE
userInteractionNONE
scopeUNCHANGED
confidentialityImpactLOW
integrityImpactNONE
availabilityImpactNONE
exploitabilityScore3.9
impactScore1.4
Scroll al inicio