autosuggest- PrestaShop module vulnerability (CVE-2024-33272)

Moduleautosuggest

Score

6.8 Medium

Date publish

29-04-2024

Versiones afectadas

  • Less than 2.0.0

Description

SQL injection vulnerability in KnowBand for PrestaShop autosuggest before 2.0.0 allows an attacker to run arbitrary SQL commands via the AutosuggestSearchModuleFrontController::initContent(), and AutosuggestSearchModuleFrontController::getKbProducts() components.

References

Metrics

cvssMetricV31
source134c704f-9b21-4f2e-91b3-4a467353bcc0
typeSecondary
version3.1
vectorStringCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:L
baseScore6.8
baseSeverityMEDIUM
attackVectorNETWORK
attackComplexityLOW
privilegesRequiredLOW
userInteractionREQUIRED
scopeUNCHANGED
confidentialityImpactHIGH
integrityImpactLOW
availabilityImpactLOW
exploitabilityScore2.1
impactScore4.7
Scroll al inicio