No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 01 Jun 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 30 May 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Shopperlabs
Shopperlabs shopper |
|
| Vendors & Products |
Shopperlabs
Shopperlabs shopper |
Fri, 29 May 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, Sub-form Livewire components used in the product editor (Edit, Inventory, Seo, Shipping, Files) had no authorization on their store() method. Any authenticated panel user, regardless of role, could mutate any product's pricing, stock, SEO metadata, shipping dimensions, and attached media without holding edit_products. The affected components accepted the product ID as a public Livewire property without #[Locked], so an attacker could also target an arbitrary product by tampering with the wire payload from the client. This vulnerability is fixed in 2.8.0. | |
| Title | Shopper: Missing authorization on Product admin Livewire sub-form components | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-06-01T15:19:52.067Z
Reserved: 2026-05-19T22:16:39.504Z
Link: CVE-2026-47742
Updated: 2026-06-01T15:19:48.626Z
Status : Deferred
Published: 2026-05-29T19:16:25.900
Modified: 2026-05-29T20:17:38.110
Link: CVE-2026-47742
No data.
OpenCVE Enrichment
Updated: 2026-05-30T21:18:08Z