CVE-2018-5190: Picturespro
Critical severity, CVSS 9.8. EPSS: 1.4% chance of exploitation in the next 30 days.
PicturesPro Photo Cart 6 and 7 before Security-Patch-2018-B allows remote attackers to access arbitrary customer accounts via a modified cookie, related to pc_head.php, pc_login.php, and pc_login_page.php.
Affected products
- Picturespro Picturespro: up to and including 7.1.0
Published 2018-04-17. Last modified 2026-06-17.