CVE-2020-12120: High severity prestashop correos express vulnerability
The Correos Express addon for PrestaShop 1.6 through 1.7 allows remote attackers to obtain sensitive information, such as a service's owner password that can be used to modify orders via SOAP. Attackers can also retrieve information about orders or buyers.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-12120?
CVE-2020-12120 has a medium severity rating due to its potential to expose sensitive information.
How do I fix CVE-2020-12120?
To fix CVE-2020-12120, it is recommended to update the Correos Express addon to the latest version provided by PrestaShop.
What type of information can be exposed by CVE-2020-12120?
CVE-2020-12120 allows attackers to obtain sensitive information including service owner passwords and details about orders or buyers.
Who is affected by CVE-2020-12120?
CVE-2020-12120 affects users of the Correos Express addon for PrestaShop versions 1.6 and 1.7.
Can CVE-2020-12120 be exploited remotely?
Yes, CVE-2020-12120 can be exploited remotely by attackers to obtain sensitive information.