CVE-2018-13784
30Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 17%
from disclosure to weapon7 days
Published on NVDJul 9
1st PoC+7d
exploitation probability
17%top 3% of all CVEs
observed exploitation
nono source reports it
5 public exploit(s)
PrestaShop before 1.6.1.20 and 1.7.x before 1.7.3.4 mishandles cookie encryption in Cookie.php, Rinjdael.php, and Blowfish.php.
Affected products
n/a · n/apublic PoCs found — 5
githubgithub.com/ambionics/prestashop-exploits★ 49cve_referencewww.exploit-db.com/exploits/45046/unverifiedcve_referencewww.exploit-db.com/exploits/45047/unverifiedexploitdbwww.exploit-db.com/exploits/45046unverifiedexploitdbwww.exploit-db.com/exploits/45047unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.