nkmgls- PrestaShop module vulnerability (CVE-2023-47309)

Modulenkmgls

Score

5.4 Medium

Date publish

15-11-2023

Versiones afectadas

  • Less than 3.0.2

Description

Nukium nkmgls before version 3.0.2 is vulnerable to Cross Site Scripting (XSS) via NkmGlsCheckoutModuleFrontController::displayAjaxSavePhoneMobile.

References

https://security.friendsofpresta.org/mod...
Exploit Patch Third Party Advisory mitre.org
https://security.friendsofpresta.org/mod...
Exploit Patch Third Party Advisory

Metrics

cvssMetricV31
sourcenvd@nist.gov
typePrimary
version3.1
vectorStringCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
baseScore5.4
baseSeverityMEDIUM
attackVectorNETWORK
attackComplexityLOW
privilegesRequiredLOW
userInteractionREQUIRED
scopeCHANGED
confidentialityImpactLOW
integrityImpactLOW
availabilityImpactNONE
exploitabilityScore2.3
impactScore2.7
Scroll al inicio