CVE-2018-13784
CRITICALPrestaShop <1.6.1.20 & <1.7.3.4 - Info Disclosure
Title source: llmDescription
PrestaShop before 1.6.1.20 and 1.7.x before 1.7.3.4 mishandles cookie encryption in Cookie.php, Rinjdael.php, and Blowfish.php.
Exploits (3)
Scores
CVSS v3
9.1
EPSS
0.4953
EPSS Percentile
97.8%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Details
Status
published
Products (1)
prestashop/prestashop
< 1.6.1.20
Published
Jul 09, 2018
Tracked Since
Feb 18, 2026