In PrestaShop from version 1.5.0.0 and before version 1.7.6.6, the authentication system is malformed and an attacker is able to forge requests and execute admin commands. The problem is fixed in 1.7.6.6.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2020-07-02T17:05:25
Updated: 2024-08-04T07:52:20.910Z
Reserved: 2019-12-30T00:00:00
Link: CVE-2020-4074
Vulnrichment
No data.
NVD
Status : Modified
Published: 2020-07-02T17:15:12.763
Modified: 2024-11-21T05:32:15.397
Link: CVE-2020-4074
Redhat
No data.