Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-45448

Опубликовано: 20 сент. 2023
Источник: nvd
CVSS3: 3.5
CVSS3: 6.1
EPSS Низкий

Описание

M4 PDF plugin for Prestashop sites, in its 3.2.3 version and before, is vulnerable to an arbitrary HTML Document crafting vulnerability. The resource /m4pdf/pdf.php uses templates to dynamically create documents. In the case that the template does not exist, the application will return a fixed document with a message in mpdf format. An attacker could exploit this vulnerability by inputting a valid HTML/CSS document as the value of the parameter.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:prestashop:m4_pdf:*:*:*:*:*:prestashop:*:*
Версия до 3.2.3 (включая)

EPSS

Процентиль: 20%
0.00063
Низкий

3.5 Low

CVSS3

6.1 Medium

CVSS3

Дефекты

CWE-79
CWE-79

Связанные уязвимости

CVSS3: 3.5
github
больше 2 лет назад

M4 PDF plugin for Prestashop sites, in its 3.2.3 version and before, is vulnerable to an arbitrary HTML Document crafting vulnerability. The resource /m4pdf/pdf.php uses templates to dynamically create documents. In the case that the template does not exist, the application will return a fixed document with a message in mpdf format. An attacker could exploit this vulnerability by inputting a valid HTML/CSS document as the value of the parameter.

EPSS

Процентиль: 20%
0.00063
Низкий

3.5 Low

CVSS3

6.1 Medium

CVSS3

Дефекты

CWE-79
CWE-79