Impact
The vulnerability in PrestaShop psgdpr allows an authenticated attacker to submit arbitrary customer identifiers when creating GDPR consent log entries, resulting in forged records for other customers. This corruption of audit logs undermines the integrity of consent tracking and may cause compliance violations without overt code execution or denial of service.
Affected Systems
All installations of PrestaShop psgdpr version 1.4.3 or earlier are affected.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. EPSS indicates a very low probability of exploitation, and it is not listed in the CISA KEV catalog. The likely attack vector is through the web application using a legitimate authenticated session to submit manipulated customer IDs, as inferred from the description.
OpenCVE Enrichment