PT-2026-27009 · Mickasmt · Next-Saas-Stripe-Starter
Ghufran Khan
+1
·
Published
2026-03-22
·
Updated
2026-03-22
·
CVE-2026-4547
CVSS v2.0
4.0
Medium
| AV:N/AC:L/Au:S/C:N/I:P/A:N |
A security vulnerability has been detected in mickasmt next-saas-stripe-starter 1.0.0. Affected is the function generateUserStripe of the file actions/generate-user-stripe.ts of the component Checkout Handler. The manipulation of the argument priceId leads to business logic errors. The attack may be initiated remotely.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Next-Saas-Stripe-Starter