#VU27325 Improper access control in PrestaShop - CVE-2020-5293
Published: April 24, 2020
PrestaShop
PrestaShop SA
Description
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions on product page with combinations, attachments and specific prices. A remote authenticated attacker can bypass implemented security restrictions and gain unauthorized access to the application.