CVE-2018-19125 is a critical vulnerability affecting PrestaShop versions 1.6.x before 1.6.1.23 and 1.7.x before 1.7.4.4, allowing remote attackers to delete image directories. With a CVSS score of 7.5 (High), this vulnerability is easily exploitable over the network with low attack complexity, potentially leading to significant data integrity issues. While not currently listed on the KEV catalog or showing active exploitation, an ExploitDB entry (EDB-45964) indicates the existence of Remote Code Execution (RCE) exploit code, despite minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.6.0.1, < 1.6.1.23CPE matchmatch criteria | cpe:2.3:a:prestashop:prestashop:*:*:*:*:*:*:*:* | ||
>= 1.7.0.0, < 1.7.4.4CPE matchmatch criteria | cpe:2.3:a:prestashop:prestashop:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.