PrestaShop before 1.6.1.20 and 1.7.x before 1.7.3.4 mishandles cookie encryption in Cookie.php, Rinjdael.php, and Blowfish.php.
References
Link | Resource |
---|---|
https://github.com/PrestaShop/PrestaShop/pull/9222 | Third Party Advisory |
https://github.com/PrestaShop/PrestaShop/pull/9218 | Third Party Advisory |
http://build.prestashop.com/news/prestashop-1-7-3-4-1-6-1-20-maintenance-releases/ | Vendor Advisory |
https://www.exploit-db.com/exploits/45047/ | Exploit Third Party Advisory VDB Entry |
https://www.exploit-db.com/exploits/45046/ | Exploit VDB Entry Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2018-07-09 03:29
Updated : 2019-10-02 17:03
NVD link : CVE-2018-13784
Mitre link : CVE-2018-13784
JSON object : View
CWE
Products Affected
prestashop
- prestashop