PrestaShop CVE-2023-39526 vulnerability

Core

Score

9.8 Critical

Date publish

07-08-2023

Versiones afectadas

  • Less than 1.7.8.10
  • Versions from 8.0.0 up to but not including 8.0.5
  • Versions from 8.1.0 up to and including 8.1.0

Description

PrestaShop is an open source e-commerce web application. Versions prior to 1.7.8.10, 8.0.5, and 8.1.1 are vulnerable to remote code execution through SQL injection and arbitrary file write in the back office. Versions 1.7.8.10, 8.0.5, and 8.1.1 contain a patch. There are no known workarounds.

References

Metrics

cvssMetricV31
sourcesecurity-advisories@github.comnvd@nist.gov
typeSecondaryPrimary
version3.13.1
vectorStringCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
baseScore9.19.8
baseSeverityCRITICALCRITICAL
attackVectorNETWORKNETWORK
attackComplexityLOWLOW
privilegesRequiredHIGHNONE
userInteractionNONENONE
scopeCHANGEDUNCHANGED
confidentialityImpactHIGHHIGH
integrityImpactHIGHHIGH
availabilityImpactHIGHHIGH
exploitabilityScore2.33.9
impactScore65.9
Scroll al inicio