CVE-2020-4074
Summary
| CVE | CVE-2020-4074 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-07-02 17:15:00 UTC |
| Updated | 2023-01-27 16:42:00 UTC |
| Description | In PrestaShop from version 1.5.0.0 and before version 1.7.6.6, the authentication system is malformed and an attacker is able to forge requests and execute admin commands. The problem is fixed in 1.7.6.6. |
Risk And Classification
Problem Types: CWE-287
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Prestashop | Prestashop | All | All | All | All |
| Application | Prestashop | Prestashop | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Improper Authentication · Advisory · PrestaShop/PrestaShop · GitHub | CONFIRM | github.com | Third Party Advisory |
| Merge pull request from GHSA-ccvh-jh5x-mpg4 · PrestaShop/PrestaShop@30b6a7b · GitHub | MISC | github.com | Patch, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.