CVE-2026-92809: PrestaShop psgdpr through 1.4.3 GDPR Log Forgery
PrestaShop psgdpr versions through 1.4.3 fail to validate that GDPR consent log entries are attributed to the authenticated customer. Authenticated attackers can submit arbitrary customer identifiers to create forged consent records for other customers, corrupting audit logs.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
PrestaShop psgdprto a version that resolves this vulnerability.Fixed in 1.4.3
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker must be authenticated as a customer. The flaw is remotely reachable and does not require user interaction, but it cannot be exploited by an unauthenticated visitor based on the available information.
What can an attacker do with forged consent records?
They can submit arbitrary customer identifiers and create GDPR consent log entries attributed to other customers. The documented impact is corruption of audit logs; no confidentiality or availability impact is specified.
Which versions are affected?
PrestaShop psgdpr versions through 1.4.3 are affected. The available data does not identify a fixed version.