Show filters
95 Total Results
Displaying 41-50 of 95
Sort by:
Attacker Value
Unknown

CVE-2020-15079

Disclosure Date: July 02, 2020 (last updated February 21, 2025)
In PrestaShop from version 1.5.0.0 and before version 1.7.6.6, there is improper access control in Carrier page, Module Manager and Module Positions. The problem is fixed in version 1.7.6.6
Attacker Value
Unknown

CVE-2020-11074

Disclosure Date: July 02, 2020 (last updated February 21, 2025)
In PrestaShop from version 1.5.3.0 and before version 1.7.6.6, there is a stored XSS when using the name of a quick access item. The problem is fixed in 1.7.6.6.
Attacker Value
Unknown

CVE-2020-15082

Disclosure Date: July 02, 2020 (last updated February 21, 2025)
In PrestaShop from version 1.6.0.1 and before version 1.7.6.6, the dashboard allows rewriting all configuration variables. The problem is fixed in 1.7.6.6
Attacker Value
Unknown

CVE-2020-4074

Disclosure Date: July 02, 2020 (last updated February 21, 2025)
In PrestaShop from version 1.5.0.0 and before version 1.7.6.6, the authentication system is malformed and an attacker is able to forge requests and execute admin commands. The problem is fixed in 1.7.6.6.
Attacker Value
Unknown

CVE-2020-15083

Disclosure Date: July 02, 2020 (last updated February 21, 2025)
In PrestaShop from version 1.7.0.0 and before version 1.7.6.6, if a target sends a corrupted file, it leads to a reflected XSS. The problem is fixed in 1.7.6.6
Attacker Value
Unknown

CVE-2020-15080

Disclosure Date: July 02, 2020 (last updated February 21, 2025)
In PrestaShop from version 1.7.4.0 and before version 1.7.6.6, some files should not be in the release archive, and others should not be accessible. The problem is fixed in version 1.7.6.6 A possible workaround is to make sure `composer.json` and `docker-compose.yml` are not accessible on your server.
Attacker Value
Unknown

CVE-2020-5264

Disclosure Date: April 20, 2020 (last updated February 21, 2025)
In PrestaShop before version 1.7.6.5, there is a reflected XSS while running the security compromised page. It allows anyone to execute arbitrary action. The problem is patched in the 1.7.6.5.
Attacker Value
Unknown

CVE-2020-5269

Disclosure Date: April 20, 2020 (last updated February 21, 2025)
In PrestaShop between versions 1.7.6.1 and 1.7.6.5, there is a reflected XSS on AdminFeatures page by using the `id_feature` parameter. The problem is fixed in 1.7.6.5
Attacker Value
Unknown

CVE-2020-5287

Disclosure Date: April 20, 2020 (last updated February 21, 2025)
In PrestaShop between versions 1.5.5.0 and 1.7.6.5, there is improper access control on customers search. The problem is fixed in 1.7.6.5.
Attacker Value
Unknown

CVE-2020-5286

Disclosure Date: April 20, 2020 (last updated February 21, 2025)
In PrestaShop between versions 1.7.4.0 and 1.7.6.5, there is a reflected XSS when uploading a wrong file. The problem is fixed in 1.7.6.5