← Back

CVE-2020-7964

nvd nist
Published: Jan 24, 2020Modified: Jun 17, 2026

JSON object

Loading...
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Exploitability: 3.9 / Impact: 1.4
Source: NVD

Description

An issue was discovered in Mirumee Saleor 2.x before 2.9.1. Incorrect access control in the checkoutCustomerAttach mutations allows attackers to attach their checkouts to any user ID and consequently leak user data (e.g., name, address, and previous orders of any other customer).

Affected (1)

Products: Mirumee: Saleor
1 product
Saleor
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
From 2.0.0 to 2.9.1

References (4)

Timeline

No history available yet.