VYPR
Vendor

Common-Services

Products
4
CVEs
5
Across products
5
Status
Private

Products

4

Recent CVEs

5
  • CVE-2023-40921CriDec 14, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in functions/point_list.php in Common Services soliberte before v4.3.03 allows attackers to obtain sensitive information via the lat and lng parameters.

  • CVE-2024-25844HigMar 3, 2024
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Common-Services "So Flexibilite" (soflexibilite) module for PrestaShop before version 4.1.26, allows remote attackers to escalate privileges and obtain sensitive information via debug file.

  • CVE-2023-45382HigNov 17, 2023
    risk 0.49cvss 7.5epss 0.01

    In the module "SoNice Retour" (sonice_retour) up to version 2.1.0 from Common-Services for PrestaShop, a guest can download personal information without restriction by performing a path traversal attack. Due to a lack of permissions control and a lack of control in the path name…

  • CVE-2023-45383HigOct 18, 2023
    risk 0.49cvss 7.5epss 0.01

    In the module "SoNice etiquetage" (sonice_etiquetage) up to version 2.5.9 from Common-Services for PrestaShop, a guest can download personal information without restriction by performing a path traversal attack. Due to a lack of permissions control and a lack of control in the…

  • CVE-2024-25841MedFeb 27, 2024
    risk 0.38cvss 5.9epss 0.00

    In the module "So Flexibilite" (soflexibilite) from Common-Services for PrestaShop < 4.1.26, a guest (authenticated customer) can perform Cross Site Scripting (XSS) injection.