advanced_loyalty_program- PrestaShop module vulnerability (CVE-2023-48926)

Moduleadvanced_loyalty_program

Score

5.3 Medium

Date publish

16-01-2024

Versiones afectadas

  • Less than 2.3.4

Description

An issue in 202 ecommerce Advanced Loyalty Program: Loyalty Points before v2.3.4 for PrestaShop allows unauthenticated attackers to arbitrarily change an order status.

References

Metrics

cvssMetricV31
sourcenvd@nist.gov134c704f-9b21-4f2e-91b3-4a467353bcc0
typePrimarySecondary
version3.13.1
vectorStringCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:NCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
baseScore5.35.3
baseSeverityMEDIUMMEDIUM
attackVectorNETWORKNETWORK
attackComplexityLOWLOW
privilegesRequiredNONENONE
userInteractionNONENONE
scopeUNCHANGEDUNCHANGED
confidentialityImpactNONENONE
integrityImpactLOWLOW
availabilityImpactNONENONE
exploitabilityScore3.93.9
impactScore1.41.4
Scroll al inicio