CVE-2020-15160
high-risk
Published 2020-09-24
PrestaShop from version 1.7.5.0 and before version 1.7.6.8 is vulnerable to a blind SQL Injection attack in the Catalog Product edition page with location parameter. The problem is fixed in 1.7.6.8
Do I need to act?
!
18.6% chance of exploitation in next 30 days
EPSS score — higher than 81% of all CVEs
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
!
1 public exploit available
+
Fix available
Upgrade to: 69f840d7f626769431c9c0ae9ad8ef1a327571c0, 3fa0dfa5a8f4b149c7c90b948a12b4f5999a5ef8
9
CVSS 9.8/10
Critical
NETWORK
/ LOW complexity
Affected Products (1)
Affected Vendors
References (8)
Third Party Advisory
http://packetstormsecurity.com/files/162140/PrestaShop-1.7.6.7-SQL-Injection.htm...
Third Party Advisory
https://github.com/PrestaShop/PrestaShop/releases/tag/1.7.6.8
Third Party Advisory
https://github.com/PrestaShop/PrestaShop/security/advisories/GHSA-fghq-8h87-826g
Third Party Advisory
http://packetstormsecurity.com/files/162140/PrestaShop-1.7.6.7-SQL-Injection.htm...
Third Party Advisory
https://github.com/PrestaShop/PrestaShop/releases/tag/1.7.6.8
Third Party Advisory
https://github.com/PrestaShop/PrestaShop/security/advisories/GHSA-fghq-8h87-826g
50
/ 100
high-risk
Severity
32/34 · Critical
Exploitability
13/34 · Low
Exposure
5/34 · Minimal