Description
Lack of authentication in NPM’s package @evershop/evershop before version 1.0.0-rc.9, allows remote attackers to obtain sensitive information via improper authorization in GraphQL endpoints.
Recommendation
Update the @evershop/evershop package to the latest compatible version. Followings are version details:
- Affected version(s): < 1.0.0-rc.9
- Patched version(s): 1.0.0-rc.9
References
Could your website be exposed too?
SmartScanner can check your website for EverShop vulnerable to improper authorization in GraphQL endpoints and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Cross-site Scripting in evershop - CVE-2023-46499
- Code execution in evershop - CVE-2023-46498
- Directory Traversal in evershop - CVE-2023-46497
- EverShop at risk to unauthorized access via weak HMAC secret - CVE-2023-46943


