Missing Authentication for Critical Function in Saleor
Moderate severity
GitHub Reviewed
Published
Jul 28, 2021
to the GitHub Advisory Database
•
Updated Feb 1, 2023
Description
Published by the National Vulnerability Database
Jan 24, 2020
Reviewed
Jul 27, 2021
Published to the GitHub Advisory Database
Jul 28, 2021
Last updated
Feb 1, 2023
An issue was discovered in Mirumee Saleor 2.x before 2.9.1. Incorrect access control in the checkoutCustomerAttach mutations allows attackers to attach their checkouts to any user ID and consequently leak user data (e.g., name, address, and previous orders of any other customer).
References