Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Shopper: Missing authorization on Product admin Livewire sub-form components
Vulnerability Description
Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, Sub-form Livewire components used in the product editor (Edit, Inventory, Seo, Shipping, Files) had no authorization on their store() method. Any authenticated panel user, regardless of role, could mutate any product's pricing, stock, SEO metadata, shipping dimensions, and attached media without holding edit_products. The affected components accepted the product ID as a public Livewire property without #[Locked], so an attacker could also target an arbitrary product by tampering with the wire payload from the client. This vulnerability is fixed in 2.8.0.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Vulnerability Type
授权机制缺失
Vulnerability Title
shopper 安全漏洞
Vulnerability Description
shopper是Shopper Labs开源的一个无头电商管理后台。 shopper 2.8.0之前版本存在安全漏洞,该漏洞源于产品编辑器中的子表单Livewire组件未对store()方法进行授权,任何经过身份验证的面板用户无论角色如何均可修改任意产品的定价、库存、SEO元数据、运输尺寸和附件媒体,且组件将产品ID作为公共Livewire属性而未加#[Locked]锁定,攻击者可通过篡改客户端wire有效载荷定位任意产品。
CVSS Information
N/A
Vulnerability Type
N/A