PrestaShop CVE-2018-13784 vulnerability

Core

Score

9.1 Critical

Date publish

09-07-2018

Versiones afectadas

  • Less than 1.6.1.20
  • Versions from 1.7.0.0 up to but not including 1.7.3.4

Description

PrestaShop before 1.6.1.20 and 1.7.x before 1.7.3.4 mishandles cookie encryption in Cookie.php, Rinjdael.php, and Blowfish.php.

References

https://github.com/PrestaShop/PrestaShop...
Third Party Advisory mitre.org
https://github.com/PrestaShop/PrestaShop...
Third Party Advisory mitre.org
https://www.exploit-db.com/exploits/4504...
Exploit Third Party Advisory VDB Entry mitre.org
https://www.exploit-db.com/exploits/4504...
Exploit Third Party Advisory VDB Entry mitre.org
https://www.exploit-db.com/exploits/4504...
Exploit Third Party Advisory VDB Entry
https://www.exploit-db.com/exploits/4504...
Exploit Third Party Advisory VDB Entry

Metrics

cvssMetricV30
sourcenvd@nist.gov
typePrimary
version3.0
vectorStringCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
baseScore9.1
baseSeverityCRITICAL
attackVectorNETWORK
attackComplexityLOW
privilegesRequiredNONE
userInteractionNONE
scopeUNCHANGED
confidentialityImpactHIGH
integrityImpactHIGH
availabilityImpactNONE
exploitabilityScore3.9
impactScore5.2
cvssMetricV2
sourcenvd@nist.gov
typePrimary
version2.0
vectorStringAV:N/AC:L/Au:N/C:P/I:P/A:N
baseScore6.4
accessVectorNETWORK
accessComplexityLOW
authenticationNONE
confidentialityImpactPARTIAL
integrityImpactPARTIAL
availabilityImpactNONE
baseSeverityMEDIUM
exploitabilityScore10
impactScore4.9
acInsufInfoFalse
obtainAllPrivilegeFalse
obtainUserPrivilegeFalse
obtainOtherPrivilegeFalse
userInteractionRequiredFalse
Scroll al inicio