blockreassurance- PrestaShop module vulnerability (CVE-2023-47109)

Moduleblockreassurance

Score

8.1 High

Date publish

08-11-2023

Versiones afectadas

  • Less than 5.1.4

Description

PrestaShop blockreassurance adds an information block aimed at offering helpful information to reassure customers that the store is trustworthy. When adding a block in blockreassurance module, a BO user can modify the http request and give the path of any file in the project instead of an image. When deleting the block from the BO, the file will be deleted. It is possible to make the website completely unavailable by removing index.php for example. This issue has been patched in version 5.1.4.

References

Metrics

cvssMetricV31
sourcesecurity-advisories@github.comnvd@nist.gov
typeSecondaryPrimary
version3.13.1
vectorStringCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:HCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
baseScore5.58.1
baseSeverityMEDIUMHIGH
attackVectorNETWORKNETWORK
attackComplexityLOWLOW
privilegesRequiredHIGHLOW
userInteractionNONENONE
scopeUNCHANGEDUNCHANGED
confidentialityImpactLOWNONE
integrityImpactNONEHIGH
availabilityImpactHIGHHIGH
exploitabilityScore1.22.8
impactScore4.25.2
Scroll al inicio