CVE-2018-19125: High severity Prestashop PrestaShop vulnerability
Published Nov 9, 2018
·Updated
PrestaShop 1.6.x before 1.6.1.23 and 1.7.x before 1.7.4.4 allows remote attackers to delete an image directory.
Affected Software
2 affected components
Prestashop PrestaShop>=1.6.0.1<1.6.1.23
Prestashop PrestaShop>=1.7.0.0<1.7.4.4
Remediation
Patch Available
Patch Available
Event History
Nov 9, 2018
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-19125?
CVE-2018-19125 is classified as a high-severity vulnerability due to the potential for remote attacks to delete image directories.
2
How do I fix CVE-2018-19125?
To fix CVE-2018-19125, upgrade PrestaShop to version 1.6.1.23 or later for 1.6.x or to version 1.7.4.4 or later for 1.7.x.
3
What versions of PrestaShop are affected by CVE-2018-19125?
CVE-2018-19125 affects PrestaShop versions 1.6.x before 1.6.1.23 and 1.7.x before 1.7.4.4.
4
Can CVE-2018-19125 be exploited remotely?
Yes, CVE-2018-19125 can be exploited by remote attackers, which poses a significant security risk.
5
What kind of vulnerability is CVE-2018-19125?
CVE-2018-19125 is a directory deletion vulnerability that allows unauthorized access to delete image directories.