Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-56830— Shopper: Incomplete fix for GHSA-h4mp-g9c6-xwph: Media sub-form store() still lacks authorization

Quick assessment

Affected
shopperlabs shopper
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Shopper 是一款无头(Headless)电子商务管理面板。在 2.9.2 版本之前,一项针对商品子表单的安全加固变更存在遗漏,导致位于 文件中的 方法未像其他同级子表单那样实施 授权检查。 因此,任何拥有 权限的已认证员工用户均可调用 Livewire 的 操作,替换已初始化 Media 组件的商品的缩略图和画廊图片,即使该用户不具备商品编辑权限。由于商品绑定关系是固定的,攻击者无法通过客户端 ID 替换将更新重定向到任意其他商品,因此影响范围仅限于其编辑页面曾被加载过的商品。 该漏洞已在 2.9.2 版本中

CVSS 6.5 · Medium

Affected Version Matrix 1

VendorProduct Version RangeStatus
shopperlabs shopper < 2.9.2 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-56830

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Shopper: Incomplete fix for GHSA-h4mp-g9c6-xwph: Media sub-form store() still lacks authorization
Source: CVE Program / CVE List V5
Vulnerability Description
Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.2, an earlier product sub-form hardening change left store() in packages/admin/src/Livewire/Components/Products/Form/Media.php without the edit_products authorization check used by sibling sub-forms. An authenticated staff user with browse_products can invoke the Livewire store action and replace the thumbnail and gallery images for a product whose Media component was initialized, even without product-edit permission. The product binding is locked, so the attacker cannot redirect the update to an arbitrary product through client-side ID substitution, and the impact is limited to products whose edit pages were loaded. This issue is fixed in version 2.9.2.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制缺失
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
shopperlabs shopper < 2.9.2 -

II. Public POCs for CVE-2026-56830

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-56830

登录查看更多情报信息。

Patches & Fixes for CVE-2026-56830 (2)

Vendor Advisories for CVE-2026-56830 (1)

Vendor Pages for CVE-2026-56830 (1)

Same Patch Batch · shopperlabs · 2026-09-15 · 5 CVEs total

CVE-2026-56827 8.1 HIGH Shopper: Authorization bypass in Filament bulk actions allows browse-only staff to mass-de
CVE-2026-56825 8.1 HIGH Shopper: Missing authorization on product removal actions in CollectionProducts component
CVE-2026-56829 8.1 HIGH Shopper: Unauthorized inventory stock manipulation via unlocked variant property in Varian
CVE-2026-56831 6.5 MEDIUM Shopper: Negative discount values accepted and propagated through order calculation pipeli

IV. Related Vulnerabilities

V. Comments for CVE-2026-56830

No comments yet


Leave a comment