Medium severity5.3NVD Advisory· Published Jul 2, 2020· Updated Jun 17, 2026
CVE-2020-15080
CVE-2020-15080
Description
In PrestaShop from version 1.7.4.0 and before version 1.7.6.6, some files should not be in the release archive, and others should not be accessible. The problem is fixed in version 1.7.6.6 A possible workaround is to make sure composer.json and docker-compose.yml are not accessible on your server.
Affected products
3cpe:2.3:a:prestashop:prestashop:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:prestashop:prestashop:*:*:*:*:*:*:*:*range: >1.7.4.0,<1.7.6.6
- (no CPE)range: 1.7.4.0 <= v < 1.7.6.6
- (no CPE)range: >= 1.7.4.0, <1.7.6.6
Patches
Vulnerability mechanics
References
2- github.com/PrestaShop/PrestaShop/commit/35ef7e9d892287c302df1fc5aa05ecfc6f15bc76nvdPatchThird Party Advisory
- github.com/PrestaShop/PrestaShop/security/advisories/GHSA-492w-2pp5-xhvgnvdThird Party Advisory
News mentions
0No linked articles in our index yet.