Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Shopper: Authorization bypass in multiple Livewire admin components
Vulnerability Description
Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, Multiple Filament actions on the admin Order detail and Order shipments table were callable by an authenticated low-privilege user without the permission required to mutate orders. The order detail actions cancel, mark paid, mark complete, capture payment, archive, and start processing were callable with the read-only read_orders permission and did not require edit_orders. capturePayment could trigger an actual PSP capture (real funds movement). The order shipments table actions mark delivered and edit tracking were callable with the read-only browse_orders permission. A user with read access to orders could therefore alter the lifecycle of every order in the panel and trigger real-world payment captures. This vulnerability is fixed in 2.8.0.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Vulnerability Type
授权机制不恰当
Vulnerability Title
shopper 安全漏洞
Vulnerability Description
shopper是Shopper Labs开源的一个无头电商管理后台。 shopper 2.8.0之前版本存在安全漏洞,该漏洞源于管理员订单详情和订单发货表上的多个Filament操作可由经过身份验证的低权限用户调用,无需修改订单权限,可能导致具有只读访问权限的用户更改订单生命周期并触发真实支付捕获。
CVSS Information
N/A
Vulnerability Type
N/A