CVE-2018-5682: Prestashop

Medium severity, CVSS 5.3. EPSS: 0.9% chance of exploitation in the next 30 days.

PrestaShop 1.7.2.4 allows user enumeration via the Reset Password feature, by noticing which reset attempts do not produce a "This account does not exist" error message.

Affected products

Published 2018-01-13. Last modified 2026-06-17.