In the module “Image: WebP, Compress, Zoom, Lazy load, Alt & More” (ultimateimagetool) in versions up to 2.1.02 from Advanced Plugins for PrestaShop, a guest can download personal informations without restriction by performing a path traversal attack..This CVE has a CVSS3.1 score of 7.5 and a Base Severity of HIGH.
Info | Details |
---|---|
CVE ID | CVE-2023-30200 |
CVE State | PUBLISHED |
BaseScore | 7.5 |
BaseSeverity | HIGH |
VectorString | CVSS:3.1/AC:L/AV:N/A:N/C:H/I:N/PR:N/S:U/UI:N |
Version | NA |
References for CVE-2023-30200 :
https://github.com/PrestaShop/PrestaShop/blob/6c05518b807d014ee8edb811041e3de232520c28/classes/Tools.php#L1247
https://security.friendsofpresta.org/modules/2023/07/20/ultimateimagetool.html
Metric Type | Metric Score |
---|---|
AttackVector(AV) | NETWORK |
AttackComplexity(AC) | LOW |
PrivilegesRequired(PR) | NONE |
UserInteraction(UI) | NONE |
Scope(S) | UNCHANGED |
Confidentiality(C) | HIGH |
Availability(A) | NONE |
Integrity(I) | NONE |