Vulnerabilities/

EverShop is vulnerable to Unauthorized Order Information Access (IDOR)

Severity:
Low

Description

A vulnerability was detected in EverShop up to 2.0.1. Affected is an unknown function of the file /src/modules/oms/graphql/types/Order/Order.resolvers.js of the component Order Handler. The manipulation of the argument uuid results in improper control of resource identifiers. The attack may be performed from remote.

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
@evershop/evershop
Anything's wrong? Let us know Last updated on December 12, 2025