Description
A vulnerability was detected in EverShop up to 2.0.1. Affected is an unknown function of the file /src/modules/oms/graphql/types/Order/Order.resolvers.js of the component Order Handler. The manipulation of the argument uuid results in improper control of resource identifiers. The attack may be performed from remote.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 2.1.0
References
Could your website be exposed too?
SmartScanner can check your website for EverShop is vulnerable to Unauthorized Order Information Access (IDOR) and gives you actionable findings to investigate.
Start a free scanRelated Issues
- EverShop at risk to unauthorized access via weak HMAC secret - CVE-2023-46943
- @kilocode/cli Vulnerable to Exposure of Sensitive Information to an Unauthorized Actor - CVE-2026-8766
- Microsoft Playwright MCP Server vulnerable to DNS Rebinding Attack; Allows Attackers Access to All Server Tools - CVE-2025-9611
- evershop allows unauthenticated attackers to force server to initiate HTTP request via "GET /images" API - CVE-2025-67427


