VYPR
High severity7.5NVD Advisory· Published Jul 9, 2019· Updated Jun 17, 2026

CVE-2019-13461

CVE-2019-13461

Description

In PrestaShop before 1.7.6.0 RC2, the id_address_delivery and id_address_invoice parameters are affected by an Insecure Direct Object Reference vulnerability due to a guessable value sent to the web application during checkout. An attacker could leak personal customer information. This is PrestaShop bug #14444.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

5
  • cpe:2.3:a:prestashop:prestashop:*:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:prestashop:prestashop:*:*:*:*:*:*:*:*range: <=1.7.5.2
    • cpe:2.3:a:prestashop:prestashop:1.7.6.0:beta1:*:*:*:*:*:*
    • cpe:2.3:a:prestashop:prestashop:1.7.6.0:rc1:*:*:*:*:*:*
    • (no CPE)range: <1.7.6.0 RC2
  • PrestaShop/PrestaShopdescription

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.