Back to the list

CVE-2026-50986 Cross Site Request Forgery (CSRF) on Administrative Mandate

PrestaShop module, Administrative Mandate (totadministrativemandate) edited by 202 ecommerce <= 1.8.1 is vulnerable to Cross Site Request Forgery (CSRF).

The payment validation controller has no CSRF token. An attacker can create an order in an awaiting status by hijacking a link.

Summary

Published at: 2026-07-29
Advisory source: 202-ecommerce.com
Platform: PrestaShop
Product: totadministrativemandate
Impacted release: <= 1.8.1 (1.8.2 patch)
Product author: 202-ecommerce.com
Weakness: CWE-352 (CSRF)
Severity: medium (5.3)

Possible malicious usage

Due to a leak of verification in the core of PrestaShop, an attacker can create an order in a country where the Administrative Mandate method is not available.

CVSS base metrics

Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope (S): Unchanged
Confidentiality (C): None
Integrity (I): Low
Availability (A): None

Timeline

  • 2026-04-09: 202-ecommerce discover the vulnerability durring an internal audit
  • 2026-04-09: 202-ecommerce request a CVE ID from Mitre
  • 2026-05-15: 202-ecommerce publish the fix release 1.8.2 on PrestaShop Marketplace
  • 2026-07-20: Mittre assign a CVE ID
  • 2026-07-29: Pubication of the CVE

Links