CVE-2023-46942
13.01.2024, 02:15
Lack of authentication in NPM's package @evershop/evershop before version 1.0.0-rc.8, allows remote attackers to obtain sensitive information via improper authorization in GraphQL endpoints.Enginsight
Vendor | Product | Version |
---|---|---|
evershop | evershop | 1.0.0:beta |
evershop | evershop | 1.0.0:beta1 |
evershop | evershop | 1.0.0:beta2 |
evershop | evershop | 1.0.0:beta3 |
evershop | evershop | 1.0.0:beta4 |
evershop | evershop | 1.0.0:beta5 |
evershop | evershop | 1.0.0:rc1 |
evershop | evershop | 1.0.0:rc2 |
evershop | evershop | 1.0.0:rc3 |
evershop | evershop | 1.0.0:rc5 |
evershop | evershop | 1.0.0:rc6 |
evershop | evershop | 1.0.0:rc7 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References