以下是该漏洞描述的中文翻译: Shopper 是一个无头(Headless)电子商务管理面板。在 2.9.2 之前,位于 、 、 、 和 中的 功能缺少服务端授权检查,而对应页面原本仅需具备 、 、 、 或 权限即可访问。这意味着仅拥有“浏览”权限的员工用户可以调用 来批量删除属性或标签,也可以调用 或 来更改属性、品牌、分类或供应商的可见性。这些操作可能会破坏商品变体(product variants),并严重干扰前台商品目录的可见性。公告中指出的逐条操作(per-record actions)和对比页面(com
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| shopperlabs | shopper | < 2.9.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| shopperlabs | shopper | < 2.9.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-56825 | 8.1 HIGH | Shopper: Missing authorization on product removal actions in CollectionProducts component |
| CVE-2026-56829 | 8.1 HIGH | Shopper: Unauthorized inventory stock manipulation via unlocked variant property in Varian |
| CVE-2026-56830 | 6.5 MEDIUM | Shopper: Incomplete fix for GHSA-h4mp-g9c6-xwph: Media sub-form store() still lacks author |
| CVE-2026-56831 | 6.5 MEDIUM | Shopper: Negative discount values accepted and propagated through order calculation pipeli |
No comments yet