Improper access control in PrestaShop - CVE-2020-15079
Published: July 2, 2020 / Updated: May 4, 2026
PrestaShop
PrestaShop SA
Description
The vulnerability allows a remote user to access restricted administrative functionality.
The vulnerability exists due to improper access control in Carrier page, Module Manager and Module Positions when handling requests. A remote user can send a specially crafted request to access restricted administrative functionality.