
Cloud Vulnerability DB
A community-led vulnerabilities database
A security vulnerability was identified in PrestaShop versions before 1.7.6.9, tracked as CVE-2020-26224. The vulnerability was discovered and disclosed on November 16, 2020, affecting the order management functionality of the e-commerce platform. The issue allows unauthorized users to access and list all orders placed on a PrestaShop website by exploiting the shopping cart recreation feature (GitHub Advisory).
The vulnerability stems from improper access control in the submitReorder function within the OrderController.php file. The security flaw exists because the original code failed to verify user authentication before allowing access to order recreation functionality. The vulnerability has been assigned a High severity rating with a CVSS 3.0 score, and the attack vector is described as Network-based with Low attack complexity and No privileges required (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N) (GitHub Advisory).
The exploitation of this vulnerability allows attackers to view all orders placed on a PrestaShop website without authentication. This represents a significant privacy breach as it exposes sensitive customer order information to unauthorized users (GitHub Advisory).
The vulnerability can be exploited by abusing the shopping cart recreation function, which is designed to allow users to recreate a cart from a previously placed order. The attack requires no special privileges or user interaction, making it relatively straightforward to exploit (GitHub Advisory).
The vulnerability has been fixed in PrestaShop version 1.7.6.9. The patch implements proper authentication checks before allowing access to the order recreation functionality, ensuring that only logged-in users can access their own orders. Users are strongly advised to upgrade to version 1.7.6.9 or later to address this security issue (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."