PrestaShop Authorization Bypass Through User-Controlled Key Vulnerability - CVE-2019-13461 - Vulnerability Database

PrestaShop Authorization Bypass Through User-Controlled Key Vulnerability - CVE-2019-13461

High
Reference: CVE-2019-13461
Title: PrestaShop Authorization Bypass Through User-Controlled Key Vulnerability
Overview:

In PrestaShop before 1.7.6.0 RC2 the id_address_delivery and id_address_invoice parameters are affected by an Insecure Direct Object Reference vulnerability due to a guessable value sent to the web application during checkout. An attacker could leak personal customer information. This is PrestaShop bug 14444.