First published: Sat Jan 13 2018(Updated: )
PrestaShop 1.7.2.4 allows user enumeration via the Reset Password feature, by noticing which reset attempts do not produce a "This account does not exist" error message.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Prestashop Prestashop | =1.7.2.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-5682 is classified as a medium severity vulnerability.
To mitigate CVE-2018-5682, update to a later version of PrestaShop where this vulnerability has been addressed.
CVE-2018-5682 is an information disclosure vulnerability that allows for user enumeration.
CVE-2018-5682 specifically affects PrestaShop version 1.7.2.4.
Yes, CVE-2018-5682 can be exploited remotely through the Reset Password feature.