Use of Less Trusted Source in PrestaShop - #VU144204
Published: August 18, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass access controls and spoof the client IP address.
The vulnerability exists due to use of a less trusted source in X-Forwarded-For header handling when processing requests forwarded through a reverse proxy, load balancer, or CDN. A remote attacker can supply a forged X-Forwarded-For header value to bypass access controls and spoof the client IP address.
Only deployments behind a reverse proxy, load balancer, or CDN are affected; shops where visitors connect directly to the web server are not affected.