fieldpopupnewsletter- PrestaShop module vulnerability (CVE-2023-39676)

Modulefieldpopupnewsletter

Score

6.1 Medium

Date publish

08-09-2023

Versiones afectadas

  • Versions from 1.0.0 up to and including 1.0.0

Description

FieldPopupNewsletter Prestashop Module v1.0.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the callback parameter at ajax.php.

References

Metrics

cvssMetricV31
sourcenvd@nist.gov
typePrimary
version3.1
vectorStringCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
baseScore6.1
baseSeverityMEDIUM
attackVectorNETWORK
attackComplexityLOW
privilegesRequiredNONE
userInteractionREQUIRED
scopeCHANGED
confidentialityImpactLOW
integrityImpactLOW
availabilityImpactNONE
exploitabilityScore2.8
impactScore2.7
Scroll al inicio