In PrestaShop from version 1.5.0.0 and before version 1.7.6.6, there is improper access control in Carrier page, Module Manager and Module Positions. The problem is fixed in version 1.7.6.6
2020-07-02T17:15:12.107
2024-11-21T05:04:46.063
Modified
CVSSv3.1: 6.4 (MEDIUM)
AV:N/AC:L/Au:S/C:P/I:P/A:N
8.0
4.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | prestashop | prestashop | < 1.7.6.6 | Yes |