CVE-2026-50986 Cross Site Request Forgery (CSRF) sur Mandat Administratif
PrestaShop module, Mandat Administratif totadministrativemandate édité par 202 ecommerce <= 1.8.1 est vulnerable à une Cross Site Request Forgery (CSRF).
Le controlleur de validation du paiement ne dispose pas d’un token anti-CSRF. Un attaquant peut alors créer une commande à l’insu d’un visisteur par le détournement de liens (par exemple via un phishing …).
Summary
Published at: 2026-07-29
Advisory source: 202-ecommerce.com
Platform: PrestaShop
Product: totadministrativemandate
Impacted release: <= 1.8.1 (1.8.2 patch)
Product author: 202-ecommerce.com
Weakness: CWE-352 (CSRF)
Severity: medium (5.3)
Possible malicious usage
A cause d’une faiblesse du core de PrestaShop, l’attaquant peut créer une commande dans un pays par Mandat Administatif alors que ce moyen de paiement n’est pas configuré pour être actif sur ce pays. La commande est quoi qu’il arrive créé dans un statut « En attente de paiement ».
CVSS base metrics
Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope (S): Unchanged
Confidentiality (C): None
Integrity (I): Low
Availability (A): None
Timeline
- 2026-04-09: 202-ecommerce discover the vulnerability durring an internal audit
- 2026-04-09: 202-ecommerce request a CVE ID from Mitre
- 2026-05-15: 202-ecommerce publish the fix release 1.8.2 on PrestaShop Marketplace
- 2026-07-20: Mittre assign a CVE ID
- 2026-07-29: Pubication of the CVE