PrestaShop Files or Directories Accessible to External Parties Vulnerability - CVE-2020-5250 - Vulnerability Database

PrestaShop Files or Directories Accessible to External Parties Vulnerability - CVE-2020-5250

Medium
Reference: CVE-2020-5250
Title: PrestaShop Files or Directories Accessible to External Parties Vulnerability
Overview:

In PrestaShop before version 1.7.6.4 when a customer edits their address they can freely change the id_address in the form and thus steal someone else39s address. It is the same with CustomerForm you are able to change the id_customer and change all information of all accounts. The problem is patched in version 1.7.6.4.