helpdesk- PrestaShop module vulnerability (CVE-2024-34992)

Modulehelpdesk

Score

8.8 High

Date publish

24-06-2024

Versiones afectadas

  • Less than 2.4.0

Description

SQL Injection vulnerability in the module "Help Desk - Customer Support Management System" (helpdesk) up to version 2.4.0 from FME Modules for PrestaShop allows attackers to obtain sensitive information and cause other impacts via 'Tickets::getsearchedtickets()'

References

Metrics

cvssMetricV31
source134c704f-9b21-4f2e-91b3-4a467353bcc0
typeSecondary
version3.1
vectorStringCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
baseScore8.8
baseSeverityHIGH
attackVectorNETWORK
attackComplexityLOW
privilegesRequiredLOW
userInteractionNONE
scopeUNCHANGED
confidentialityImpactHIGH
integrityImpactHIGH
availabilityImpactHIGH
exploitabilityScore2.8
impactScore5.9
Scroll al inicio