CVE-2020-4074: Improper Authentication
In PrestaShop from version 1.5.0.0 and before version 1.7.6.6, the authentication system is malformed and an attacker is able to forge requests and execute admin commands. The problem is fixed in 1.7.6.6.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2020-4074?
CVE-2020-4074 is a vulnerability in PrestaShop versions 1.5.0.0 to 1.7.6.6 that allows an attacker to forge requests and execute admin commands.
How severe is CVE-2020-4074?
CVE-2020-4074 has a severity rating of critical with a score of 9.8.
What is the affected software for CVE-2020-4074?
The affected software for CVE-2020-4074 is PrestaShop versions 1.5.0.0 to 1.7.6.6.
How can I fix CVE-2020-4074?
To fix CVE-2020-4074, update PrestaShop to version 1.7.6.6 or later.
Where can I find more information about CVE-2020-4074?
You can find more information about CVE-2020-4074 in the references provided by PrestaShop: [Link 1](https://github.com/PrestaShop/PrestaShop/commit/30b6a7bdaca9cb940d3ce462906dbb062499fc30) and [Link 2](https://github.com/PrestaShop/PrestaShop/security/advisories/GHSA-ccvh-jh5x-mpg4).