CVE-2020-15102 Information

Description

In PrestaShop Dashboard Productions before version 2.1.0 there is improper authorization which enables an attacker to change the configuration. The problem is fixed in 2.1.0.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Reference

https://github.com/PrestaShop/dashproducts/commit/f0799c13628a9b9ca6ca75c085b083d924a8ea7e https://github.com/PrestaShop/dashproducts/security/advisories/GHSA-6292-4qpg-hvfg

Attack Complexity

LOW

Privileges Required

LOW

User Interaction Required

LOW

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

NONE

Availability Impact

HIGH

Base Score

NONE

Base Severity

6.5

Share on: