PrestaShop Exposure of Sensitive Information to an Unauthorized Actor Vulnerability - CVE-2020-15080 - Vulnerability Database

PrestaShop Exposure of Sensitive Information to an Unauthorized Actor Vulnerability - CVE-2020-15080

Medium
Reference: CVE-2020-15080
Title: PrestaShop Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
Overview:

In PrestaShop from version 1.7.4.0 and before version 1.7.6.6 some files should not be in the release archive and others should not be accessible. The problem is fixed in version 1.7.6.6 A possible workaround is to make sure composer.json and docker-compose.yml are not accessible on your server.