Cross Site Request Forgery Vulnerability in PrestaShop Payment Module
CVE-2026-50986
8.8HIGH
What is CVE-2026-50986?
The PrestaShop module named totadministrativemandate, versions prior to 1.8.1, is susceptible to Cross Site Request Forgery (CSRF) attacks. This vulnerability occurs because the payment validation controller fails to implement a CSRF token, allowing unauthorized users to manipulate order confirmations. By hijacking specific links, attackers can confirm orders that are in an awaiting status, potentially leading to financial loss and a breach of customer trust.
