ZeroHour

CVE-2020-4074

CVSS 3.1
9.8 critical
EPSS
2%p77
Published
()
Modified
Description

In PrestaShop from version 1.5.0.0 and before version 1.7.6.6, the authentication system is malformed and an attacker is able to forge requests and execute admin commands. The problem is fixed in 1.7.6.6.

Vendors
prestashop
Products
prestashop
Ecosystems
E-commerce
Weakness
CWE-287
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.