Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Saleor has a user enumeration vulnerability due to different error messages
Vulnerability Description
Saleor is an e-commerce platform. From 2.10.0 to before 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118, the requestEmailChange() mutation was revealing the existence of user-provided email addresses in error messages. This vulnerability is fixed in 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118.
CVSS Information
N/A
Vulnerability Type
响应差异性信息暴露
Vulnerability Title
saleor 安全漏洞
Vulnerability Description
saleor是Saleor Commerce开源的一个接口软件。 saleor 3.23.0a3之前版本、3.22.47之前版本、3.21.54之前版本和3.20.118之前版本存在安全漏洞,该漏洞源于错误消息泄露用户提供的电子邮件地址存在性。
CVSS Information
N/A
Vulnerability Type
N/A