An issue was discovered in Mirumee Saleor 2.x before 2.9.1. Incorrect access control in the checkoutCustomerAttach mutations allows attackers to attach their checkouts to any user ID and consequently leak user data (e.g., name, address, and previous orders of any other customer).
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2020-01-24T19:38:03

Updated: 2020-01-24T19:38:03

Reserved: 2020-01-24T00:00:00


Link: CVE-2020-7964

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2020-01-24T20:15:11.050

Modified: 2021-07-21T11:39:23.747


Link: CVE-2020-7964

JSON object: View

cve-icon Redhat Information

No data.

CWE