PT-2018-12183 · Prestashop · Prestashop

Charles Fol

·

Published

2018-07-09

·

Updated

2019-10-03

·

CVE-2018-13784

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions PrestaShop versions prior to 1.6.1.20 PrestaShop versions 1.7.x prior to 1.7.3.4
Description The issue concerns the mishandling of cookie encryption in certain PHP files, specifically Cookie.php, Rinjdael.php, and Blowfish.php.
Recommendations For PrestaShop versions prior to 1.6.1.20, update to version 1.6.1.20 or later. For PrestaShop versions 1.7.x prior to 1.7.3.4, update to version 1.7.3.4 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2018-13784

Affected Products

Prestashop