Unrated severityNVD Advisory· Published Jul 2, 2020· Updated Aug 4, 2024
Information disclosure in release archive in PrestaShop
CVE-2020-15080
Description
In PrestaShop from version 1.7.4.0 and before version 1.7.6.6, some files should not be in the release archive, and others should not be accessible. The problem is fixed in version 1.7.6.6 A possible workaround is to make sure composer.json and docker-compose.yml are not accessible on your server.
Affected products
1- Range: >= 1.7.4.0, <1.7.6.6
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- github.com/PrestaShop/PrestaShop/commit/35ef7e9d892287c302df1fc5aa05ecfc6f15bc76mitrex_refsource_MISC
- github.com/PrestaShop/PrestaShop/security/advisories/GHSA-492w-2pp5-xhvgmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.