Show filters
95 Total Results
Displaying 41-50 of 95
Sort by:
Attacker Value
Unknown
CVE-2020-15079
Disclosure Date: July 02, 2020 (last updated February 21, 2025)
In PrestaShop from version 1.5.0.0 and before version 1.7.6.6, there is improper access control in Carrier page, Module Manager and Module Positions. The problem is fixed in version 1.7.6.6
0
Attacker Value
Unknown
CVE-2020-11074
Disclosure Date: July 02, 2020 (last updated February 21, 2025)
In PrestaShop from version 1.5.3.0 and before version 1.7.6.6, there is a stored XSS when using the name of a quick access item. The problem is fixed in 1.7.6.6.
0
Attacker Value
Unknown
CVE-2020-15082
Disclosure Date: July 02, 2020 (last updated February 21, 2025)
In PrestaShop from version 1.6.0.1 and before version 1.7.6.6, the dashboard allows rewriting all configuration variables. The problem is fixed in 1.7.6.6
0
Attacker Value
Unknown
CVE-2020-4074
Disclosure Date: July 02, 2020 (last updated February 21, 2025)
In PrestaShop from version 1.5.0.0 and before version 1.7.6.6, the authentication system is malformed and an attacker is able to forge requests and execute admin commands. The problem is fixed in 1.7.6.6.
0
Attacker Value
Unknown
CVE-2020-15083
Disclosure Date: July 02, 2020 (last updated February 21, 2025)
In PrestaShop from version 1.7.0.0 and before version 1.7.6.6, if a target sends a corrupted file, it leads to a reflected XSS. The problem is fixed in 1.7.6.6
0
Attacker Value
Unknown
CVE-2020-15080
Disclosure Date: July 02, 2020 (last updated February 21, 2025)
In PrestaShop from version 1.7.4.0 and before version 1.7.6.6, some files should not be in the release archive, and others should not be accessible. The problem is fixed in version 1.7.6.6 A possible workaround is to make sure `composer.json` and `docker-compose.yml` are not accessible on your server.
0
Attacker Value
Unknown
CVE-2020-5264
Disclosure Date: April 20, 2020 (last updated February 21, 2025)
In PrestaShop before version 1.7.6.5, there is a reflected XSS while running the security compromised page. It allows anyone to execute arbitrary action. The problem is patched in the 1.7.6.5.
0
Attacker Value
Unknown
CVE-2020-5269
Disclosure Date: April 20, 2020 (last updated February 21, 2025)
In PrestaShop between versions 1.7.6.1 and 1.7.6.5, there is a reflected XSS on AdminFeatures page by using the `id_feature` parameter. The problem is fixed in 1.7.6.5
0
Attacker Value
Unknown
CVE-2020-5287
Disclosure Date: April 20, 2020 (last updated February 21, 2025)
In PrestaShop between versions 1.5.5.0 and 1.7.6.5, there is improper access control on customers search. The problem is fixed in 1.7.6.5.
0
Attacker Value
Unknown
CVE-2020-5286
Disclosure Date: April 20, 2020 (last updated February 21, 2025)
In PrestaShop between versions 1.7.4.0 and 1.7.6.5, there is a reflected XSS when uploading a wrong file. The problem is fixed in 1.7.6.5
0