productdesigner- PrestaShop module vulnerability (CVE-2024-26469)

Moduleproductdesigner

Score

8.1 High

Date publish

03-03-2024

Versiones afectadas

  • Less than 1.178.36

Description

Server-Side Request Forgery (SSRF) vulnerability in Tunis Soft "Product Designer" (productdesigner) module for PrestaShop before version 1.178.36, allows remote attackers to cause a denial of service (DoS) and escalate privileges via the url parameter in the postProcess() method.

References

Metrics

cvssMetricV31
source134c704f-9b21-4f2e-91b3-4a467353bcc0
typeSecondary
version3.1
vectorStringCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
baseScore8.1
baseSeverityHIGH
attackVectorNETWORK
attackComplexityLOW
privilegesRequiredLOW
userInteractionNONE
scopeUNCHANGED
confidentialityImpactHIGH
integrityImpactNONE
availabilityImpactHIGH
exploitabilityScore2.8
impactScore5.2
Scroll al inicio