Description PrestaShop 1.6.x before 1.6.1.23 and 1.7.x before 1.7.4.4 allows remote attackers to delete an image directory. Remediation References CVE-2018-19125 Related Vulnerabilities WordPress 3.8.x Multiple Vulnerabilities (3.8 - 3.8.33) Elgg Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2011-2935) WordPress Plugin BuddyDrive Cross-Site Scripting (1.2.2) WordPress Plugin The Events Calendar Security Bypass (3.11.2) Oracle JRE CVE-2013-3744 Vulnerability (CVE-2013-3744) Severity High Classification CVE-2018-19125 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N Tags Missing Update Known Vulnerabilities