GHSA-6pq6-crw9-522h
Dashboard / Vulnerabilities / GHSA-6pq6-crw9-522h
Summary: Cezerin Unauthorized Acces
Details: Cezerin v0.33.0 allows unauthorized order-information modification because certain internal attributes can be overwritten via a conflicting name when processing order requests. Hence, a malicious customer can manipulate an order (e.g., its payment status or shipping fee) by adding additional attributes to user-input during the PUT `/ajax/cart` operation for a checkout, because of `getValidDocumentForUpdate` in `api/server/services/orders/orders.js`.
References: https://nvd.nist.gov/vuln/detail/CVE-2019-18608, https://github.com/cezerin/cezerin, https://github.com/cl0udz/vulnerabilities/blob/master/cezerin-manipulate_order_information/README.md
Affected packages
Package
Name: cezerin
Purl: pkg:npm/cezerin
Affected ranges
Type: SEMVER
Events:
