PrestaShop affected by time based enumeration in FO login form
Moderate severity
GitHub Reviewed
Published
Feb 3, 2026
in
PrestaShop/PrestaShop
•
Updated Feb 6, 2026
Package
Affected versions
>= 9.0.0-alpha.1, < 9.0.3
< 8.2.4
Patched versions
9.0.3
8.2.4
Description
Published to the GitHub Advisory Database
Feb 3, 2026
Reviewed
Feb 3, 2026
Published by the National Vulnerability Database
Feb 6, 2026
Last updated
Feb 6, 2026
Impact
A time-based user enumeration vulnerability in the user authentication functionality of PrestaShop. This vulnerability allows an attacker to determine whether a customer account exists in the system by measuring response times.
Patches
8.2.4 and 9.0.3
Workarounds
none
References
Found by Lam Yiu Tung
References