CVE-2026-92809
PrestaShop psgdpr through 1.4.3 GDPR Log Forgery
CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th
PrestaShop psgdpr versions through 1.4.3 fail to validate that GDPR consent log entries are attributed to the authenticated customer. Authenticated attackers can submit arbitrary customer identifiers to create forged consent records for other customers, corrupting audit logs.
| CWE | CWE-639 |
| Vendor | prestashop |
| Product | psgdpr |
| Published | Sep 16, 2026 |
Stay Ahead of the Next One
Get instant alerts for prestashop psgdpr
Be the first to know when new medium vulnerabilities affecting prestashop psgdpr are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
None
Affected Versions
PrestaShop / psgdpr
0 โค 1.4.3
References
github.com: https://github.com/geo-chen/oss/blob/main/prestashop.md#finding-1-idor---authenticated-customers-can-forge-gdpr-consent-records-for-arbitrary-customers github.com: https://github.com/PrestaShop/psgdpr/blob/v1.4.3/controllers/front/FrontAjaxGdpr.php#L28-L54 github.com: https://github.com/PrestaShop/psgdpr vulncheck.com: https://www.vulncheck.com/advisories/prestashop-psgdpr-through-1.4.3-gdpr-log-forgery
Credits
George Chen