CVE-2020-5250: Possible information disclosure in PrestaShop
In PrestaShop before version 1.7.6.4, when a customer edits their address, they can freely change the idaddress in the form, and thus steal someone else's address. It is the same with CustomerForm, you are able to change the idcustomer and change all information of all accounts. The problem is patched in version 1.7.6.4.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
prestaShopto a version that resolves this vulnerability.Fixed in 1.7.6.4
Event History
Frequently Asked Questions
What is the severity of CVE-2020-5250?
CVE-2020-5250 has been classified as a high severity vulnerability due to the potential for unauthorized access to customer address information.
How do I fix CVE-2020-5250?
To fix CVE-2020-5250, upgrade PrestaShop to version 1.7.6.4 or later, which includes the necessary security patches.
What type of vulnerability is CVE-2020-5250?
CVE-2020-5250 is an access control vulnerability that allows users to manipulate identifiers in forms to gain unauthorized access to other users' data.
In which versions of PrestaShop is CVE-2020-5250 present?
CVE-2020-5250 affects all versions of PrestaShop prior to 1.7.6.4.
What can attackers do with CVE-2020-5250?
Attackers can exploit CVE-2020-5250 to change customer addresses and account information, potentially leading to identity theft or fraud.