google_integrator- PrestaShop module vulnerability (CVE-2023-6921)

Modulegoogle_integrator

Score

9.8 Critical

Date publish

08-01-2024

Versiones afectadas

  • Less than 2.1.4

Description

Blind SQL Injection vulnerability in PrestaShow Google Integrator (PrestaShop addon) allows for data extraction and modification. This attack is possible via command insertion in one of the cookies.

References

Metrics

cvssMetricV31
sourcecvd@cert.plnvd@nist.gov
typeSecondaryPrimary
version3.13.1
vectorStringCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
baseScore9.89.1
baseSeverityCRITICALCRITICAL
attackVectorNETWORKNETWORK
attackComplexityLOWLOW
privilegesRequiredNONENONE
userInteractionNONENONE
scopeUNCHANGEDUNCHANGED
confidentialityImpactHIGHHIGH
integrityImpactHIGHHIGH
availabilityImpactHIGHNONE
exploitabilityScore3.93.9
impactScore5.95.2
Scroll al inicio