idxquickorder- PrestaShop module vulnerability (CVE-2023-46989)

Moduleidxquickorder

Score

7.8 High

Date publish

28-12-2023

Versiones afectadas

  • Less than 1.4.0

Description

SQL Injection vulnerability in the Innovadeluxe Quick Order module for PrestaShop before v.1.4.0, allows local attackers to execute arbitrary code via the getProducts() function in the productlist.php file.

References

https://security.friendsofpresta.org/mod...
Patch Third Party Advisory mitre.org

Metrics

cvssMetricV31
sourcenvd@nist.gov
typePrimary
version3.1
vectorStringCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
baseScore7.8
baseSeverityHIGH
attackVectorLOCAL
attackComplexityLOW
privilegesRequiredLOW
userInteractionNONE
scopeUNCHANGED
confidentialityImpactHIGH
integrityImpactHIGH
availabilityImpactHIGH
exploitabilityScore1.8
impactScore5.9
Scroll al inicio