CVE-2020-26224

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
16/11/2020
Last modified:
30/11/2020

Description

In PrestaShop before version 1.7.6.9 an attacker is able to list all the orders placed on the website without being logged by abusing the function that allows a shopping cart to be recreated from an order already placed. The problem is fixed in 1.7.6.9.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:prestashop:prestashop:*:*:*:*:*:*:*:* 1.7.6.9 (excluding)