Medium severity6.4NVD Advisory· Published Jul 2, 2020· Updated Jun 17, 2026
CVE-2020-15079
CVE-2020-15079
Description
In PrestaShop from version 1.5.0.0 and before version 1.7.6.6, there is improper access control in Carrier page, Module Manager and Module Positions. The problem is fixed in version 1.7.6.6
Affected products
3cpe:2.3:a:prestashop:prestashop:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:prestashop:prestashop:*:*:*:*:*:*:*:*range: >1.5.0.0,<1.7.6.6
- (no CPE)range: 1.5.0.0 <= version < 1.7.6.6
- (no CPE)range: >= 1.5.0.0, < 1.7.6.6
Patches
Vulnerability mechanics
References
2- github.com/PrestaShop/PrestaShop/commit/8833d9504cc5d69a2a6d10197f56f0c11443cbfanvdPatchThird Party Advisory
- github.com/PrestaShop/PrestaShop/security/advisories/GHSA-xp3x-3h8q-c386nvdThird Party Advisory
News mentions
0No linked articles in our index yet.