Description
In PrestaShop from version 1.5.0.0 and before version 1.7.6.6, there is improper access control in Carrier page, Module Manager and Module Positions. The problem is fixed in version 1.7.6.6
Remediation
References
Related Vulnerabilities
Joomla Permissions, Privileges, and Access Controls Vulnerability (CVE-2006-4476)
WordPress Plugin Nextend Google Connect Unspecified Vulnerability (1.5.3)
WordPress Plugin Asgaros Forum Multiple SQL Injection Vulnerabilities (1.15.12)
Roundcube Incorrect Resource Transfer Between Spheres Vulnerability (CVE-2026-35540)