CVE-2019-13461: High severity prestashop vulnerability
In PrestaShop before 1.7.6.0 RC2, the idaddressdelivery and idaddressinvoice parameters are affected by an Insecure Direct Object Reference vulnerability due to a guessable value sent to the web application during checkout. An attacker could leak personal customer information. This is PrestaShop bug #14444.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-13461?
CVE-2019-13461 has a medium severity rating due to its potential to expose personal customer information.
How do I fix CVE-2019-13461?
To fix CVE-2019-13461, upgrade your PrestaShop installation to version 1.7.6.0 RC2 or later.
What types of personal information can be exposed by CVE-2019-13461?
CVE-2019-13461 can potentially expose addresses and other personal customer data during checkout.
What versions of PrestaShop are affected by CVE-2019-13461?
Versions of PrestaShop prior to 1.7.6.0 RC2, including 1.7.5.2 and 1.7.6.0 beta1 and rc1, are affected by CVE-2019-13461.
Is CVE-2019-13461 an urgent security vulnerability?
Yes, CVE-2019-13461 is considered urgent as it could lead to data leaks, necessitating prompt remediation.