Vulnerability Details CVE-2020-15080
In PrestaShop from version 1.7.4.0 and before version 1.7.6.6, some files should not be in the release archive, and others should not be accessible. The problem is fixed in version 1.7.6.6 A possible workaround is to make sure `composer.json` and `docker-compose.yml` are not accessible on your server.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 43.1%
CVSS Severity
CVSS v3 Score 5.3
CVSS v2 Score 5.0
Products affected by CVE-2020-15080
-
cpe:2.3:a:prestashop:prestashop:1.7.4.1
-
cpe:2.3:a:prestashop:prestashop:1.7.4.2
-
cpe:2.3:a:prestashop:prestashop:1.7.4.3
-
cpe:2.3:a:prestashop:prestashop:1.7.4.4
-
cpe:2.3:a:prestashop:prestashop:1.7.5.0
-
cpe:2.3:a:prestashop:prestashop:1.7.5.1
-
cpe:2.3:a:prestashop:prestashop:1.7.5.2
-
cpe:2.3:a:prestashop:prestashop:1.7.6.0
-
cpe:2.3:a:prestashop:prestashop:1.7.6.1
-
cpe:2.3:a:prestashop:prestashop:1.7.6.2
-
cpe:2.3:a:prestashop:prestashop:1.7.6.3
-
cpe:2.3:a:prestashop:prestashop:1.7.6.4
-
cpe:2.3:a:prestashop:prestashop:1.7.6.5