Vulnerability library
Security checkDecember 12, 2025

EverShop is vulnerable to Unauthorized Order Information Access (IDOR)

Understand the exposure, see the recommended fix, and check whether your own website has related weaknesses.

Check your website

Find this and other vulnerabilities with a free scan.

Your scan runs on your computer. No account required.

Description

A vulnerability was detected in EverShop up to 2.0.1. Affected is an unknown function of the file /src/modules/oms/graphql/types/Order/Order.resolvers.js of the component Order Handler. The manipulation of the argument uuid results in improper control of resource identifiers. The attack may be performed from remote.

Recommendation

No fix is available yet. Followings are affected versions:

  • <= 2.1.0

References

Could your website be exposed too?

SmartScanner can check your website for EverShop is vulnerable to Unauthorized Order Information Access (IDOR) and gives you actionable findings to investigate.

Start a free scan

Related Issues

See something that needs correcting? Let us knowUpdated December 12, 2025