Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Timuric

#48414de 53,624
5.3CVSS total
Vulnerabilidades · 1
PT-2019-11556
5.3
2019-07-15
Mirumee · Saleor · CVE-2019-1010304
Name of the Vulnerable Software and Affected Versions: Saleor versions 2.0.0 through 2.3.0 Description: The issue is related to Incorrect Access Control, allowing an unauthenticated user to access the GraphQL API, which is publicly exposed under the `/graphql/` URL. This enables the user to fetch products data, potentially including admin-restricted shop's revenue data. The impact of this issue is considered Important. Recommendations: For Saleor versions 2.0.0 through 2.3.0, update to version 2.3.1 to resolve the issue. As a temporary workaround, consider restricting access to the `/graphql/` URL to minimize the risk of exploitation.