PrestaShop psgdpr versions through 1.4.3 fail to validate that GDPR consent log entries are attributed to the authenticated customer. Authenticated attackers can submit arbitrary customer identifiers to create forged consent records for other customers, corrupting audit logs.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 16 Sep 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | PrestaShop psgdpr versions through 1.4.3 fail to validate that GDPR consent log entries are attributed to the authenticated customer. Authenticated attackers can submit arbitrary customer identifiers to create forged consent records for other customers, corrupting audit logs. | |
| Title | PrestaShop psgdpr through 1.4.3 GDPR Log Forgery | |
| First Time appeared |
Prestashop
Prestashop prestashop |
|
| Weaknesses | CWE-639 | |
| CPEs | cpe:2.3:a:prestashop:prestashop:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Prestashop
Prestashop prestashop |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-16T20:32:56.067Z
Reserved: 2026-09-16T19:55:00.619Z
Link: CVE-2026-92809
No data.
Status : Received
Published: 2026-09-16T21:17:30.570
Modified: 2026-09-16T21:17:30.570
Link: CVE-2026-92809
No data.
OpenCVE Enrichment
No data.
Weaknesses