icon

We found results for “

CVE-2024-29888

Good to know:

icon

Date: March 27, 2024

Saleor is an e-commerce platform that serves high-volume companies. When using `Pickup: Local stock only` click-and-collect as a delivery method in specific conditions the customer could overwrite the warehouse address with its own, which exposes its address as click-and-collect address. This issue has been patched in versions: `3.14.61`, `3.15.37`, `3.16.34`, `3.17.32`, `3.18.28`, `3.19.15`.

Language: Python

Severity Score

Severity Score

Weakness Type (CWE)

Exposure of Private Personal Information to an Unauthorized Actor

CWE-359

Top Fix

icon

Upgrade Version

Upgrade to version 3.14.61,3.15.37,3.16.34,3.17.32,3.18.28,3.19.15

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): HIGH
Privileges Required (PR): NONE
User Interaction (UI): REQUIRED
Scope (S): UNCHANGED
Confidentiality (C): LOW
Integrity (I): LOW
Availability (A): NONE

Do you need more information?

Contact Us