PT-2020-14236 · Prestashop · Prestashop

R00Tpgp

·

Published

2020-09-24

·

Updated

2021-05-05

·

CVE-2020-15160

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PrestaShop versions 1.7.5.0 through 1.7.6.7
Description The issue concerns a blind SQL Injection attack in the Catalog Product edition page, specifically with the location parameter. This allows for unauthorized access to database information. The problem is fixed in version 1.7.6.8.
Recommendations For PrestaShop versions 1.7.5.0 through 1.7.6.7, update to version 1.7.6.8 to resolve the issue. As a temporary workaround, consider restricting access to the Catalog Product edition page until the update is applied.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-15160
GHSA-FGHQ-8H87-826G

Affected Products

Prestashop