CVE-2026-92809
OrtaTeknik Veri (Otomatik)
- CVSS Skoru
- 4.3
- EPSS
- —
- CWE
- CWE-639
- KEV Durumu
- Hayır
PrestaShop psgdpr sürümleri 1.4.3'e kadar, GDPR onay log girişlerinin kimlik doğrulamış müşteriye ait olduğunu doğrulamada başarısız olur. Kimlik doğrulamış saldırganlar, diğer müşteriler için sahte onay kayıtları oluşturarak denetim günlüklerini bozmak için keyfi müşteri tanımlayıcıları gönderebilir.
Orijinal açıklama (İngilizce)
PrestaShop psgdpr versions through 1.4.3 fail to validate that GDPR consent log entries are attributed to the authenticated customer. Authenticated attackers can submit arbitrary customer identifiers to create forged consent records for other customers, corrupting audit logs.
Referanslar
- https://github.com/PrestaShop/psgdpr
- https://github.com/PrestaShop/psgdpr/blob/v1.4.3/controllers/front/FrontAjaxGdpr.php#L28-L54
- https://github.com/geo-chen/oss/blob/main/prestashop.md#finding-1-idor---authenticated-customers-can-forge-gdpr-consent-records-for-arbitrary-customers
- https://www.vulncheck.com/advisories/prestashop-psgdpr-through-1.4.3-gdpr-log-forgery
Bu CVE için henüz editoryal inceleme yapılmadı. Sadece otomatik teknik veri gösteriliyor.
