Description
Cezerin v0.33.0 allows unauthorized order-information modification because certain internal attributes can be overwritten via a conflicting name when processing order requests. Hence, a malicious customer can manipulate an order (e.g.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 0.33.0
References
Related Issues
- Exposure of Sensitive Information to an Unauthorized Actor in nanoid - CVE-2021-23566
- Cross-Site Scripting in editor.md - CVE-2019-9737
- Deserialization of Untrusted Data in bson - bson - CVE-2019-2391
- Sandbox Breakout / Arbitrary Code Execution in safer-eval - safer-eval - GHSA-r3x4-wr4h-pw33 - CVE-2019-10759
You might also like:
- Tags:
- npm
- cezerin
Anything's wrong? Let us know Last updated on September 26, 2023


