#VU24806 Information disclosure in Saleor - CVE-2020-7964
Published: January 31, 2020
Saleor
Mirumee Labs
Description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to incorrect access control in the "checkoutCustomerAttach" mutations. A remote attacker can attach their checkouts to any user ID and consequently leak user data (e.g., name, address, and previous orders of any other customer)