Shopper 是一个无头(Headless)电子商务管理面板。在 2.9.2 版本之前, 中的 方法在缺少 权限授权的情况下被暴露,并且由于缺少 Livewire 的 属性,其公开变量 可被客户端任意修改。因此,任何已认证的管理面板用户(包括仅拥有 权限的普通员工)都可以通过组件状态选择任意的产品变体(variant)和库存位置(inventory location),然后提交正数或负数的数量调整请求。这使得仅具备浏览权限的员工能够针对当前页面之外的任意变体,恶意增加库存、减少库存或强制将其设置为缺货状态。该问题
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| shopperlabs | shopper | < 2.9.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| shopperlabs | shopper | < 2.9.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-56827 | 8.1 HIGH | Shopper: Authorization bypass in Filament bulk actions allows browse-only staff to mass-de |
| CVE-2026-56825 | 8.1 HIGH | Shopper: Missing authorization on product removal actions in CollectionProducts component |
| CVE-2026-56830 | 6.5 MEDIUM | Shopper: Incomplete fix for GHSA-h4mp-g9c6-xwph: Media sub-form store() still lacks author |
| CVE-2026-56831 | 6.5 MEDIUM | Shopper: Negative discount values accepted and propagated through order calculation pipeli |
No comments yet