High severity8.9NVD Advisory· Published Jul 2, 2020· Updated Jun 17, 2026
CVE-2020-4074
CVE-2020-4074
Description
In PrestaShop from version 1.5.0.0 and before version 1.7.6.6, the authentication system is malformed and an attacker is able to forge requests and execute admin commands. The problem is fixed in 1.7.6.6.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:prestashop:prestashop:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:prestashop:prestashop:*:*:*:*:*:*:*:*range: >=1.5.0.0,<1.7.6.6
- (no CPE)range: 1.5.0.0 - 1.7.6.5
- (no CPE)range: >= 1.5.0.0, < 1.7.6.6
Patches
Vulnerability mechanics
References
2- github.com/PrestaShop/PrestaShop/commit/30b6a7bdaca9cb940d3ce462906dbb062499fc30nvdPatchThird Party Advisory
- github.com/PrestaShop/PrestaShop/security/advisories/GHSA-ccvh-jh5x-mpg4nvdThird Party Advisory
News mentions
0No linked articles in our index yet.