#VU27320 Improper access control in PrestaShop - CVE-2020-5279
Published: April 24, 2020
PrestaShop
PrestaShop SA
Description
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions for legacy controllers and API. A remote authenticated attacker can bypass implemented security restrictions and gain unauthorized access to the application.
- admin-dev/index.php/configure/shop/customer-preferences/
- admin-dev/index.php/improve/international/translations/
- admin-dev/index.php/improve/international/geolocation/
- admin-dev/index.php/improve/international/localization
- admin-dev/index.php/configure/advanced/performance
- admin-dev/index.php/sell/orders/delivery-slips/ - admin-dev/index.php?controller=AdminStatuses