icon

We found results for “

CVE-2024-29888

Date: March 27, 2024

Saleor is an e-commerce platform that serves high-volume companies. When using "Pickup: Local stock only" click-and-collect as a delivery method in specific conditions the customer could overwrite the warehouse address with its own, which exposes its address as click-and-collect address. This issue has been patched in versions: "3.14.61", "3.15.37", "3.16.34", "3.17.32", "3.18.28", "3.19.15".

Language: Python

Severity Score

Severity Score

Weakness Type (CWE)

Exposure of Private Personal Information to an Unauthorized Actor

CWE-359

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): HIGH
Privileges Required (PR): NONE
User Interaction (UI): REQUIRED
Scope (S): UNCHANGED
Confidentiality (C): LOW
Integrity (I): LOW
Availability (A): NONE

Do you need more information?

Contact Us