CVE-2018-13784: Critical severity prestashop vulnerability
Published Jul 9, 2018
·Updated
PrestaShop before 1.6.1.20 and 1.7.x before 1.7.3.4 mishandles cookie encryption in Cookie.php, Rinjdael.php, and Blowfish.php.
Affected Software
2 affected components
Prestashop PrestaShop<1.6.1.20
Prestashop PrestaShop>=1.7.0.0<1.7.3.4
Event History
Jul 9, 2018
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-13784?
CVE-2018-13784 is classified as a high severity vulnerability due to its impact on cookie encryption.
2
How do I fix CVE-2018-13784?
To fix CVE-2018-13784, upgrade PrestaShop to version 1.6.1.20 or 1.7.3.4 or later.
3
What systems are affected by CVE-2018-13784?
CVE-2018-13784 affects PrestaShop versions prior to 1.6.1.20 and 1.7.x before 1.7.3.4.
4
What is the impact of CVE-2018-13784?
The impact of CVE-2018-13784 includes potential unauthorized access to sensitive user data due to improper cookie encryption.
5
Who is responsible for addressing CVE-2018-13784?
It is the responsibility of PrestaShop users and administrators to apply the necessary updates to mitigate CVE-2018-13784.