CVE-2020-15082: External control of configuration setting in the dashboard in PrestaShop
Published Jul 2, 2020
·Updated
In PrestaShop from version 1.6.0.1 and before version 1.7.6.6, the dashboard allows rewriting all configuration variables. The problem is fixed in 1.7.6.6
Affected Software
1 affected component
Prestashop PrestaShop>=1.6.0.1<1.7.6.6
Remediation
Event History
Jul 2, 2020
CVE Published
via MITRE·04:50 PM
Data Sourced
via MITRE·04:50 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2020-15082?
CVE-2020-15082 is a vulnerability in PrestaShop versions 1.6.0.1 and before 1.7.6.6 that allows rewriting all configuration variables.
2
How severe is CVE-2020-15082?
CVE-2020-15082 has a severity rating of 8.8 (high).
3
How can I fix CVE-2020-15082?
CVE-2020-15082 can be fixed by updating PrestaShop to version 1.7.6.6 or higher.
4
Where can I find more information about CVE-2020-15082?
More information about CVE-2020-15082 can be found in the following references: [Link](https://github.com/PrestaShop/PrestaShop/commit/0f0d6238169a79d94f5ef28d24e60a9be8902f4b) and [Link](https://github.com/PrestaShop/PrestaShop/security/advisories/GHSA-mc98-xjm3-c4fm)