Executive brief
PrestaShop is a popular open-source e-commerce platform used to build online stores. This vulnerability allows attackers to forge their source IP address via the X-Forwarded-For header, bypassing IP-based security controls like maintenance mode allowlists and enabling tampering with security logs and evasion of fraud detection systems.
Technical details
This vulnerability is an access control issue (CWE-290) in the Tools::getRemoteAddr() function where PrestaShop incorrectly trusts and processes the X-Forwarded-For header when running behind a reverse proxy, load balancer, or CDN. An unauthenticated remote attacker can supply an arbitrary IP address via this header, and the application will use it instead of the real client IP from trusted infrastructure. This allows bypassing IP-based allowlists, forging audit and security logs, and evading geolocation checks, fraud detection, and request rate limiting. The vulnerability has been patched in PrestaShop versions 9.1.5 and 8.2.8.
Affected products
- PrestaShop PrestaShop before 8.2.8 and 9.1.5
Timeline
- 2026-09-07: disclosed
- 2026-09-07: patched: Fixed in versions 9.1.5 and 8.2.8