PrestaShop versions prior to 1.6.1.20 and 1.7.x prior to 1.7.3.4 contain a vulnerability in the way cookies are encrypted, specifically in the Cookie.php, Rinjdael.php, and Blowfish.php files. The implementation mishandles encryption, potentially allowing attackers to compromise the confidentiality and integrity of cookie data.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
This repository contains operational exploit code for PrestaShop <= 1.6.1.19, targeting CVE-2018-13784, a set of cryptographic vulnerabilities in PrestaShop's cookie handling. The structure includes: - README.md: Brief description and reference to a detailed blog post. - prestashop_aes_cbc/prestashop_cbc_read.py: Python script implementing a padding oracle attack against AES-encrypted employee cookies, allowing an attacker to read or modify any PrestaShop cookie if they have a valid one. - prestashop_blowfish_ecb/crc_xor.c: C utility for CRC manipulation, used as part of the cookie forging process in the ECB exploit. - prestashop_blowfish_ecb/exploit.py: Main Python exploit for the Blowfish ECB vulnerability. It automates the process of escalating privileges from a customer to an employee (admin) by forging valid authentication cookies, provided the customer and employee share the same password. The exploit can be adapted for other attacks, such as accessing customer accounts or extracting admin CSRF tokens. The main attack vector is web-based, requiring access to the PrestaShop web application. The exploit is operational, with working code and clear instructions for use. Several hardcoded endpoints (example URLs) are present, but these must be adapted to the actual target. The code demonstrates advanced cryptographic attacks and is not a simple detection script.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.