# 漏洞概述 **标题**: Unauthenticated information disclosure in `commerce/payments/pay` can leak some customer order data on anonymous payments **描述**: `PaymentsController::actionPay` 在提供订单号且电子邮件检查在匿名支付期间失败时…
# [Security] CORS Misconfiguration in Local Proxy Enables 1-Click API Key Abuse #1841 ## 漏洞概述 cc-switch 本地代理服务器(默认监听 `127.0.0.1:15721`)存在过度宽松的 CORS 策略(`allow_origin(Any)`),允许任意网站向代理发送跨域请求。由于代理会自动注入用户的…