7.5
CVE-2024-25842
- EPSS 0.09%
- Veröffentlicht 03.03.2024 09:15:06
- Zuletzt bearbeitet 08.05.2025 17:34:29
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
An issue was discovered in Presta World "Account Manager - Sales Representative & Dealers - CRM" (prestasalesmanager) module for PrestaShop before version 9.0, allows remote attackers to escalate privilege and obtain sensitive information via the uploadLogo() and postProcess methods.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Prestaworld ≫ Account Manager SwPlatformprestashop Version < 9.0.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.09% | 0.255 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
CWE-269 Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.