Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2020-5250 PoC — Possible information disclosure in PrestaShop

Source
Associated Vulnerability
Title: Possible information disclosure in PrestaShop (CVE-2020-5250)
Description:In PrestaShop before version 1.7.6.4, when a customer edits their address, they can freely change the id_address in the form, and thus steal someone else's address. It is the same with CustomerForm, you are able to change the id_customer and change all information of all accounts. The problem is patched in version 1.7.6.4.
Description
Labelgrup Fixer for CVE-2020-5250 vulnerability
Readme
# LabelGrup Networks, official PrestaShop Partner

![LabelGrup Logo](logo.png)

Module for PS 1.7.X to fix CVE-2020-5250 vulnerability (WIP)

Check: 
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-5250
https://github.com/PrestaShop/PrestaShop/security/advisories/GHSA-mhfc-6rhg-fxp3

Visit our website:
https://www.labelgrup.com
File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →