CVE-2020-15079

MEDIUM

PrestaShop <1.7.6.6 - Privilege Escalation

Title source: llm
STIX 2.1

Description

In PrestaShop from version 1.5.0.0 and before version 1.7.6.6, there is improper access control in Carrier page, Module Manager and Module Positions. The problem is fixed in version 1.7.6.6

Scores

CVSS v3 6.4
EPSS 0.0015
EPSS Percentile 34.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N

Details

CWE
CWE-284
Status published
Products (1)
prestashop/prestashop 1.5.0.0 - 1.7.6.6
Published Jul 02, 2020
Tracked Since Feb 18, 2026