productsalert- PrestaShop module vulnerability (CVE-2024-36683)

Moduleproductsalert

Score

7.3 High

Date publish

24-06-2024

Versiones afectadas

  • Less than 1.7.4

Description

SQL injection vulnerability in the module "Products Alert" (productsalert) before 1.7.4 from Smart Modules for PrestaShop allows attackers to obtain sensitive information and cause other impacts via the ProductsAlertAjaxProcessModuleFrontController::initContent method.

References

Metrics

cvssMetricV31
source134c704f-9b21-4f2e-91b3-4a467353bcc0
typeSecondary
version3.1
vectorStringCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
baseScore7.3
baseSeverityHIGH
attackVectorNETWORK
attackComplexityLOW
privilegesRequiredNONE
userInteractionNONE
scopeUNCHANGED
confidentialityImpactLOW
integrityImpactLOW
availabilityImpactLOW
exploitabilityScore3.9
impactScore3.4
Scroll al inicio