Логотип exploitDog
bind:CVE-2025-12919
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-12919

Количество 2

Количество 2

nvd логотип

CVE-2025-12919

3 месяца назад

A vulnerability was detected in EverShop up to 2.0.1. Affected is an unknown function of the file /src/modules/oms/graphql/types/Order/Order.resolvers.js of the component Order Handler. The manipulation of the argument uuid results in improper control of resource identifiers. The attack may be performed from remote. This attack is characterized by high complexity. The exploitability is told to be difficult. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-c73g-mx2w-cc93

3 месяца назад

EverShop is vulnerable to Unauthorized Order Information Access (IDOR)

CVSS3: 3.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-12919

A vulnerability was detected in EverShop up to 2.0.1. Affected is an unknown function of the file /src/modules/oms/graphql/types/Order/Order.resolvers.js of the component Order Handler. The manipulation of the argument uuid results in improper control of resource identifiers. The attack may be performed from remote. This attack is characterized by high complexity. The exploitability is told to be difficult. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 3.7
0%
Низкий
3 месяца назад
github логотип
GHSA-c73g-mx2w-cc93

EverShop is vulnerable to Unauthorized Order Information Access (IDOR)

CVSS3: 3.7
0%
Низкий
3 месяца назад

Уязвимостей на страницу