Shopper 是一款无头(Headless)电子商务管理面板。在 2.9.2 版本之前,一项针对商品子表单的安全加固变更存在遗漏,导致位于 文件中的 方法未像其他同级子表单那样实施 授权检查。 因此,任何拥有 权限的已认证员工用户均可调用 Livewire 的 操作,替换已初始化 Media 组件的商品的缩略图和画廊图片,即使该用户不具备商品编辑权限。由于商品绑定关系是固定的,攻击者无法通过客户端 ID 替换将更新重定向到任意其他商品,因此影响范围仅限于其编辑页面曾被加载过的商品。 该漏洞已在 2.9.2 版本中
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| shopperlabs | shopper | < 2.9.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| shopperlabs | shopper | < 2.9.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-56827 | 8.1 HIGH | Shopper: Authorization bypass in Filament bulk actions allows browse-only staff to mass-de |
| CVE-2026-56825 | 8.1 HIGH | Shopper: Missing authorization on product removal actions in CollectionProducts component |
| CVE-2026-56829 | 8.1 HIGH | Shopper: Unauthorized inventory stock manipulation via unlocked variant property in Varian |
| CVE-2026-56831 | 6.5 MEDIUM | Shopper: Negative discount values accepted and propagated through order calculation pipeli |
No comments yet