Vulnerabilities/

Cezerin Unauthorized Acces

Severity:
High

Description

Cezerin v0.33.0 allows unauthorized order-information modification because certain internal attributes can be overwritten via a conflicting name when processing order requests. Hence, a malicious customer can manipulate an order (e.g.

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
cezerin
Anything's wrong? Let us know Last updated on September 26, 2023