Vulnerability Description
The Correos Express addon for PrestaShop 1.6 through 1.7 allows remote attackers to obtain sensitive information, such as a service's owner password that can be used to modify orders via SOAP. Attackers can also retrieve information about orders or buyers.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Prestashop | Correos Express | >= 1.6, <= 1.7 |
Related Weaknesses (CWE)
References
- https://addons.prestashop.com/en/delivery-date/27273-correos-express-solutions-oVendor Advisory
- https://ia-informatica.com/it/CVE-2020-12120ExploitThird Party Advisory
- https://addons.prestashop.com/en/delivery-date/27273-correos-express-solutions-oVendor Advisory
- https://ia-informatica.com/it/CVE-2020-12120ExploitThird Party Advisory
FAQ
What is CVE-2020-12120?
CVE-2020-12120 is a vulnerability with a CVSS score of 7.5 (HIGH). The Correos Express addon for PrestaShop 1.6 through 1.7 allows remote attackers to obtain sensitive information, such as a service's owner password that can be used to modify orders via SOAP. Attacke...
How severe is CVE-2020-12120?
CVE-2020-12120 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-12120?
Check the references section above for vendor advisories and patch information. Affected products include: Prestashop Correos Express.