Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-5250

Опубликовано: 05 мар. 2020
Источник: nvd
CVSS3: 7.6
CVSS3: 6.3
CVSS2: 4.9
EPSS Низкий

Описание

In PrestaShop before version 1.7.6.4, when a customer edits their address, they can freely change the id_address in the form, and thus steal someone else's address. It is the same with CustomerForm, you are able to change the id_customer and change all information of all accounts. The problem is patched in version 1.7.6.4.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:prestashop:prestashop:*:*:*:*:*:*:*:*
Версия от 1.7.0.0 (включая) до 1.7.6.4 (исключая)

EPSS

Процентиль: 70%
0.00627
Низкий

7.6 High

CVSS3

6.3 Medium

CVSS3

4.9 Medium

CVSS2

Дефекты

CWE-285
CWE-552

EPSS

Процентиль: 70%
0.00627
Низкий

7.6 High

CVSS3

6.3 Medium

CVSS3

4.9 Medium

CVSS2

Дефекты

CWE-285
CWE-552