Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-35933


This package is a PrestaShop module that allows users to post reviews and rate products. There is a vulnerability where the attacker could steal an administrator's cookie. The issue is fixed in version 5.0.2.


Published

2022-09-02T20:15:08.510

Last Modified

2024-11-21T07:11:59.683

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.1 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-79
  • Type: Primary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application prestashop productcomments < 5.0.2 Yes

References