PrestaShop before 1.6.1.20 and 1.7.x before 1.7.3.4 mishandles cookie encryption in Cookie.php, Rinjdael.php, and Blowfish.php.
Link | Tags |
---|---|
https://www.exploit-db.com/exploits/45046/ | third party advisory vdb entry exploit |
https://github.com/PrestaShop/PrestaShop/pull/9222 | third party advisory |
http://build.prestashop.com/news/prestashop-1-7-3-4-1-6-1-20-maintenance-releases/ | vendor advisory |
https://github.com/PrestaShop/PrestaShop/pull/9218 | third party advisory |
https://www.exploit-db.com/exploits/45047/ | third party advisory vdb entry exploit |