PrestaShop versions after 1.5.0.0 and before 1.7.6.6 are vulnerable to information exposure through directory listing in the upload directory due to a missing index.php file.
id: CVE-2020-15081
info:
name: PrestaShop < 1.7.6.6 - Information Exposure via Upload Directory
...