Описание
prestashop/blockwishlist is a prestashop extension which adds a block containing the customer's wishlists. In affected versions an authenticated customer can perform SQL injection. This issue is fixed in version 2.1.1. Users are advised to upgrade. There are no known workarounds for this issue.
Ссылки
- ExploitThird Party AdvisoryVDB Entry
- PatchThird Party Advisory
- Third Party Advisory
- ExploitThird Party AdvisoryVDB Entry
- PatchThird Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2.1.1 (исключая)
cpe:2.3:a:prestashop:blockwishlist:*:*:*:*:*:*:*:*
EPSS
Процентиль: 97%
0.30399
Средний
8.1 High
CVSS3
8.8 High
CVSS3
6.5 Medium
CVSS2
Дефекты
CWE-89
Связанные уязвимости
EPSS
Процентиль: 97%
0.30399
Средний
8.1 High
CVSS3
8.8 High
CVSS3
6.5 Medium
CVSS2
Дефекты
CWE-89