Shopper: Unauthorized inventory stock manipulation
Shopper: Unauthorized inventory stock manipulation via unlocked variant property in VariantStock component. Title Unauthorized inventory stock manipulation via unlocked variant property in VariantStock component Description A lack of authorization control was discovered in the stockAction() method in packages/admin/src/Livewire/Components/Products/VariantStock.php.
- Severity
- HighCVSS 3.1 · 8.1 · github.com
- Fix
- Fixed in 2.9.2Fix recorded today
- Affected versions
- before 2.9.2
- Weakness
- CWE-862Missing Authorization
- Affects
- shopper/framework
What to do
Update to 2.9.2 or later.
Technical details
Affected software: shopper/framework
Severity breakdown
- Attack vector Network Requires network access to the vulnerable service
- Attack complexity Low Low complexity under the assessed conditions
- Privileges required Low Attacker needs a basic user account
- User interaction None No victim action needed
- Scope Unchanged Impact stays within the same security authority
- Confidentiality impact None No data disclosure
- Integrity impact High Protected data can be changed with serious impact
- Availability impact High The service can stop or suffer serious disruption
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H Open in FIRST.org calculatorReferences
- github.com · GHSA-g3f9-g5vj-p62f vendor advisory