cezerin@0.1.2 vulnerabilities

Cezerin is React and Node.js based eCommerce platform. https://cezerin.com

Direct Vulnerabilities

Known vulnerabilities in the cezerin package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • H
Improper Access Control

cezerin is a React and Node.js based eCommerce platform.

Affected versions of this package are vulnerable to Improper Access Control. Certain internal attributes (e.g., paid and tax) within getValidDocumentForUpdate in src/api/server/services/orders/orders.js function can be overwritten via a conflicting name from user-input. As such, it is possible for a malicious customer to manipulate certain order status (i.e., payment status, tax) by adding additional attributes to user-input during checkout.

How to fix Improper Access Control?

There is no fixed version for cezerin.

*