First published: Thu Jul 02 2020(Updated: )
In PrestaShop from version 1.5.0.0 and before version 1.7.6.6, the authentication system is malformed and an attacker is able to forge requests and execute admin commands. The problem is fixed in 1.7.6.6.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Prestashop Prestashop | >=1.5.0.0<1.7.6.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-4074 is a vulnerability in PrestaShop versions 1.5.0.0 to 1.7.6.6 that allows an attacker to forge requests and execute admin commands.
CVE-2020-4074 has a severity rating of critical with a score of 9.8.
The affected software for CVE-2020-4074 is PrestaShop versions 1.5.0.0 to 1.7.6.6.
To fix CVE-2020-4074, update PrestaShop to version 1.7.6.6 or later.
You can find more information about CVE-2020-4074 in the references provided by PrestaShop: [Link 1](https://github.com/PrestaShop/PrestaShop/commit/30b6a7bdaca9cb940d3ce462906dbb062499fc30) and [Link 2](https://github.com/PrestaShop/PrestaShop/security/advisories/GHSA-ccvh-jh5x-mpg4).