Skip to content

CVE-2023-30200

In the module “Image: WebP, Compress, Zoom, Lazy load, Alt & More” (ultimateimagetool) in versions up to 2.1.02 from Advanced Plugins for PrestaShop, a guest can download personal informations without restriction by performing a path traversal attack..This CVE has a CVSS3.1 score of 7.5 and a Base Severity of HIGH.

InfoDetails
CVE IDCVE-2023-30200
CVE StatePUBLISHED
BaseScore7.5
BaseSeverityHIGH
VectorStringCVSS:3.1/AC:L/AV:N/A:N/C:H/I:N/PR:N/S:U/UI:N
VersionNA

References for CVE-2023-30200 :
https://github.com/PrestaShop/PrestaShop/blob/6c05518b807d014ee8edb811041e3de232520c28/classes/Tools.php#L1247
https://security.friendsofpresta.org/modules/2023/07/20/ultimateimagetool.html

Metric TypeMetric Score
AttackVector(AV)NETWORK
AttackComplexity(AC)LOW
PrivilegesRequired(PR)NONE
UserInteraction(UI)NONE
Scope(S)UNCHANGED
Confidentiality(C)HIGH
Availability(A)NONE
Integrity(I)NONE
Tags: