7.5

CVE-2020-12120

Exploit
The Correos Express addon for PrestaShop 1.6 through 1.7 allows remote attackers to obtain sensitive information, such as a service's owner password that can be used to modify orders via SOAP. Attackers can also retrieve information about orders or buyers.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Prestashop ≫ Correos Express SwPlatform prestashop Version >= 1.6 <= 1.7
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.77% 0.752
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-732 Incorrect Permission Assignment for Critical Resource

The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.

https://addons.prestashop.com/en/delivery-date/27273-correos-express-solutions-of-urgent-transport.html
Vendor Advisory
https://ia-informatica.com/it/CVE-2020-12120
Third Party Advisory
Exploit