CVE-2020-12120

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
27/04/2020
Last modified:
21/07/2021

Description

The Correos Express addon for PrestaShop 1.6 through 1.7 allows remote attackers to obtain sensitive information, such as a service's owner password that can be used to modify orders via SOAP. Attackers can also retrieve information about orders or buyers.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:prestashop:correos_express:*:*:*:*:*:prestashop:*:* 1.6 (including) 1.7 (including)