PT-2026-94081 · Prestashop+1 · Psgdpr
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
PrestaShop psgdpr versions prior to 1.4.4
Description
The software fails to validate that GDPR consent log entries are attributed to the authenticated customer. This allows authenticated attackers to submit arbitrary customer identifiers to create forged consent records for other customers, which results in the corruption of audit logs.
Recommendations
Update PrestaShop psgdpr to version 1.4.4 or later.
Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Psgdpr