CVE-2026-50986

PrestaShop module, totadministrativemandate <1.8.1 is vulnerable to Cross Site Request Forgery (CSRF). The payment validation controller has no CSRF token. An attacker can confirm an order in an awaiting status by hijacking a link.
Configurations

No configuration.

History

No history.

Information

Published : 2026-07-31 21:17

Updated : 2026-08-31 19:33


NVD link : CVE-2026-50986

Mitre link : CVE-2026-50986

CVE.ORG link : CVE-2026-50986


JSON object : View

Products Affected

No product.

CWE
CWE-352

Cross-Site Request Forgery (CSRF)