Next SaaS Stripe Starter是mickasmt个人开发者的一个集成支付与认证的SaaS项目启动模板。 Next SaaS Stripe Starter 1.0.0版本存在安全漏洞,该漏洞源于对结账处理组件中文件actions/generate-user-stripe.ts的函数generateUserStripe的参数priceId的错误操作,可能导致业务逻辑错误。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| mickasmt | next-saas-stripe-starter | 1.0.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-4548 | 6.3 MEDIUM | mickasmt next-saas-stripe-starter update-user-role.ts updateUserrole improper authorizatio |
| CVE-2026-4549 | 3.1 LOW | mickasmt next-saas-stripe-starter Stripe API open-customer-portal.ts openCustomerPortal au |
No comments yet