PrestaShop before 1.6.1.20 and 1.7.x before 1.7.3.4 mishandles cookie encryption in Cookie.php, Rinjdael.php, and Blowfish.php.
References
Link | Resource |
---|---|
http://build.prestashop.com/news/prestashop-1-7-3-4-1-6-1-20-maintenance-releases/ | Vendor Advisory |
https://github.com/PrestaShop/PrestaShop/pull/9218 | Third Party Advisory |
https://github.com/PrestaShop/PrestaShop/pull/9222 | Third Party Advisory |
https://www.exploit-db.com/exploits/45046/ | Exploit Third Party Advisory VDB Entry |
https://www.exploit-db.com/exploits/45047/ | Exploit Third Party Advisory VDB Entry |
http://build.prestashop.com/news/prestashop-1-7-3-4-1-6-1-20-maintenance-releases/ | Vendor Advisory |
https://github.com/PrestaShop/PrestaShop/pull/9218 | Third Party Advisory |
https://github.com/PrestaShop/PrestaShop/pull/9222 | Third Party Advisory |
https://www.exploit-db.com/exploits/45046/ | Exploit Third Party Advisory VDB Entry |
https://www.exploit-db.com/exploits/45047/ | Exploit Third Party Advisory VDB Entry |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 03:47
Type | Values Removed | Values Added |
---|---|---|
References | () http://build.prestashop.com/news/prestashop-1-7-3-4-1-6-1-20-maintenance-releases/ - Vendor Advisory | |
References | () https://github.com/PrestaShop/PrestaShop/pull/9218 - Third Party Advisory | |
References | () https://github.com/PrestaShop/PrestaShop/pull/9222 - Third Party Advisory | |
References | () https://www.exploit-db.com/exploits/45046/ - Exploit, Third Party Advisory, VDB Entry | |
References | () https://www.exploit-db.com/exploits/45047/ - Exploit, Third Party Advisory, VDB Entry |
Information
Published : 2018-07-09 10:29
Updated : 2024-11-21 03:47
NVD link : CVE-2018-13784
Mitre link : CVE-2018-13784
CVE.ORG link : CVE-2018-13784
JSON object : View
Products Affected
prestashop
- prestashop
CWE