Skip to main content

Vendor archive

mirumee CVEs

Beta · best-effort

4 CVEs tagged to vendor mirumee0 Critical, 1 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2020-15085

Published Jun 30, 2020

In Saleor Storefront before version 2.10.3, request data used to authenticate customers was inadvertently cached in the browser's local storage mechanism, including credentials. A…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-7964

Published Jan 24, 2020

An issue was discovered in Mirumee Saleor 2.x before 2.9.1. Incorrect access control in the checkoutCustomerAttach mutations allows attackers to attach their checkouts to any user…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-1010304

Published Jul 15, 2019

Saleor Issue was introduced by merge commit: e1b01bad0703afd08d297ed3f1f472248312cc9c. This commit was released as part of 2.0.0 release is affected by: Incorrect Access Control.…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-13594

Published Jul 14, 2019

In Mirumee Saleor 2.7.0 (fixed in 2.8.0), CSRF protection middleware was accidentally disabled, which allowed attackers to send a POST request without a valid CSRF token and be ac…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-4 of 4 CVEsPage 1 of 1