CVE-2019-13461
In PrestaShop before 1.7.6.0 RC2, the id_address_delivery and id_address_invoice parameters are affected by an Insecure Direct Object Reference vulnerability due to a guessable value sent to the web application during checkout. An attacker could leak personal customer information. This is PrestaShop bug #14444.
- Affected products
- Prestashop
- Prestashop
- ≤ 1.7.5.2, 1.7.6.0
- Fix
- Available
- CVSS 3.0
- 7.5 HIGH
- EPSS
- 1.7% (75th percentile)
- Weakness
- CWE-639
- NVD status
- Modified
- Published
- 2019-07-09
CVE-2019-13461 at NVD
No indexed exploits for CVE-2019-13461 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2019-13461 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.