PrestaShop CVE-2025-51586 vulnerability

Core

Score

3.7 Low

Date publish

08-09-2025

Versiones afectadas

  • Less than 8.2.1

Description

An issue was discoverd in file controllers/admin/AdminLoginController.php in PrestaShop before 8.2.1 allowing attackers to gain sensitive information via the reset password feature.

References

Metrics

cvssMetricV31
source134c704f-9b21-4f2e-91b3-4a467353bcc0
typeSecondary
version3.1
vectorStringCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
baseScore3.7
baseSeverityLOW
attackVectorNETWORK
attackComplexityHIGH
privilegesRequiredNONE
userInteractionNONE
scopeUNCHANGED
confidentialityImpactLOW
integrityImpactNONE
availabilityImpactNONE
exploitabilityScore2.2
impactScore1.4
Scroll al inicio