Description
PrestaShop psgdpr versions through 1.4.3 fail to validate that GDPR consent log entries are attributed to the authenticated customer. Authenticated attackers can submit arbitrary customer identifiers to create forged consent records for other customers, corrupting audit logs.
Published: 2026-09-16
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Log Integrity Compromise
Action: Apply Patch
AI Analysis

Impact

The vulnerability in PrestaShop psgdpr allows an authenticated attacker to submit arbitrary customer identifiers when creating GDPR consent log entries, resulting in forged records for other customers. This corruption of audit logs undermines the integrity of consent tracking and may cause compliance violations without overt code execution or denial of service.

Affected Systems

All installations of PrestaShop psgdpr version 1.4.3 or earlier are affected.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity. EPSS indicates a very low probability of exploitation, and it is not listed in the CISA KEV catalog. The likely attack vector is through the web application using a legitimate authenticated session to submit manipulated customer IDs, as inferred from the description.

Generated by OpenCVE AI on September 18, 2026 at 06:20 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade PrestaShop psgdpr to a version newer than 1.4.3 to remediate the flaw.
  • Re-examine existing GDPR consent logs for suspicious entries and rebuild or invalidate compromised records.
  • Enforce strict input validation on front controllers handling consent logs so that the authenticated customer ID cannot be overridden.

Generated by OpenCVE AI on September 18, 2026 at 06:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Prestashop psgdpr
Vendors & Products Prestashop psgdpr

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Description PrestaShop psgdpr versions through 1.4.3 fail to validate that GDPR consent log entries are attributed to the authenticated customer. Authenticated attackers can submit arbitrary customer identifiers to create forged consent records for other customers, corrupting audit logs.
Title PrestaShop psgdpr through 1.4.3 GDPR Log Forgery
First Time appeared Prestashop
Prestashop prestashop
Weaknesses CWE-639
CPEs cpe:2.3:a:prestashop:prestashop:*:*:*:*:*:*:*:*
Vendors & Products Prestashop
Prestashop prestashop
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Prestashop Prestashop Psgdpr
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-17T19:24:18.452Z

Reserved: 2026-09-16T19:55:00.619Z

Link: CVE-2026-92809

cve-icon Vulnrichment

Updated: 2026-09-17T18:41:12.587Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T21:17:30.570

Modified: 2026-09-22T20:43:58.793

Link: CVE-2026-92809

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T20:03:06Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key