CVE-2020-4074

HIGH

Prestashop < 1.7.6.6 - Authentication Bypass

Title source: rule
STIX 2.1

Description

In PrestaShop from version 1.5.0.0 and before version 1.7.6.6, the authentication system is malformed and an attacker is able to forge requests and execute admin commands. The problem is fixed in 1.7.6.6.

Scores

CVSS v3 8.9
EPSS 0.0043
EPSS Percentile 62.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L

Details

CWE
CWE-287
Status published
Products (1)
prestashop/prestashop 1.5.0.0 - 1.7.6.6
Published Jul 02, 2020
Tracked Since Feb 18, 2026