Vulnerability library
Security checkJuly 26, 2024

EverShop vulnerable to improper authorization in GraphQL endpoints

Understand the exposure, see the recommended fix, and check whether your own website has related weaknesses.

Check your website

Find this and other vulnerabilities with a free scan.

Your scan runs on your computer. No account required.

Description

Lack of authentication in NPM’s package @evershop/evershop before version 1.0.0-rc.9, allows remote attackers to obtain sensitive information via improper authorization in GraphQL endpoints.

Recommendation

Update the @evershop/evershop package to the latest compatible version. Followings are version details:

  • Affected version(s): < 1.0.0-rc.9
  • Patched version(s): 1.0.0-rc.9

References

Could your website be exposed too?

SmartScanner can check your website for EverShop vulnerable to improper authorization in GraphQL endpoints and gives you actionable findings to investigate.

Start a free scan

Related Issues

See something that needs correcting? Let us knowUpdated July 26, 2024