VYPR

Saleor Storefront

by Saleor

CVEs (2)

  • CVE-2024-29036MedMar 20, 2024
    risk 0.00cvss 4.3epss 0.01

    Saleor Storefront is software for building e-commerce experiences. Prior to commit 579241e75a5eb332ccf26e0bcdd54befa33f4783, when any user authenticates in the storefront, anonymous users are able to access their data. The session is leaked through cache and can be accessed by…

  • CVE-2020-15085MedJun 30, 2020
    risk 0.00cvss 6.9epss 0.01

    In Saleor Storefront before version 2.10.3, request data used to authenticate customers was inadvertently cached in the browser's local storage mechanism, including credentials. A malicious user with direct access to the browser could extract the email and password. In versions…