Headline
GHSA-ggpm-9qfx-mhwg: EverShop vulnerable to improper authorization in GraphQL endpoints
Lack of authentication in NPM’s package @evershop/evershop before version 1.0.0-rc.9, allows remote attackers to obtain sensitive information via improper authorization in GraphQL endpoints.
EverShop vulnerable to improper authorization in GraphQL endpoints
Moderate severity GitHub Reviewed Published Jan 13, 2024 to the GitHub Advisory Database • Updated Jan 16, 2024