MEDIUM
Improper access control in PrestaShop
Published Jul 2, 2020
6.4
MEDIUMCVSS 3.1
EPSS 0.58%
Description
In PrestaShop from version 1.5.0.0 and before version 1.7.6.6, there is improper access control in Carrier page, Module Manager and Module Positions. The problem is fixed in version 1.7.6.6
Affected products
-
- Version >= 1.5.0.0, < 1.7.6.6StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| PrestaShop | PrestaShop | n/a |
|
- > 1.5.0.0 · < 1.7.6.6
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-7207 Advisory
- https://github.com/PrestaShop/PrestaShop/commit/8833d9504cc5d69a2a6d10197f56f0c11443cbfa x_refsource_MISCPatchThird Party Advisory
- https://github.com/PrestaShop/PrestaShop/security/advisories/GHSA-xp3x-3h8q-c386 x_refsource_CONFIRMThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-7207 | Advisory | |
| https://github.com/PrestaShop/PrestaShop/commit/8833d9504cc5d69a2a6d10197f56f0c11443cbfa | x_refsource_MISCPatchThird Party Advisory | |
| https://github.com/PrestaShop/PrestaShop/security/advisories/GHSA-xp3x-3h8q-c386 | x_refsource_CONFIRMThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Jul 2, 2020
Updated Aug 4, 2024
Reserved Jun 25, 2020
Link CVE-2020-15079
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2020-7207 Assigner GitHub_M
Published Jul 2, 2020
Updated Aug 4, 2024
Exploited since n/a
Link EUVD-2020-7207