An issue in EverShop NPM versions before v.1.0.0-rc.8 allows a remote attacker to obtain sensitive information and execute arbitrary code via the /deleteCustomer/route.json file.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Evershop | Evershop | 1.0.0-beta (including) | 1.0.0-beta (including) |
Evershop | Evershop | 1.0.0-beta1 (including) | 1.0.0-beta1 (including) |
Evershop | Evershop | 1.0.0-beta2 (including) | 1.0.0-beta2 (including) |
Evershop | Evershop | 1.0.0-beta3 (including) | 1.0.0-beta3 (including) |
Evershop | Evershop | 1.0.0-beta4 (including) | 1.0.0-beta4 (including) |
Evershop | Evershop | 1.0.0-beta5 (including) | 1.0.0-beta5 (including) |
Evershop | Evershop | 1.0.0-rc1 (including) | 1.0.0-rc1 (including) |
Evershop | Evershop | 1.0.0-rc2 (including) | 1.0.0-rc2 (including) |
Evershop | Evershop | 1.0.0-rc3 (including) | 1.0.0-rc3 (including) |
Evershop | Evershop | 1.0.0-rc5 (including) | 1.0.0-rc5 (including) |
Evershop | Evershop | 1.0.0-rc6 (including) | 1.0.0-rc6 (including) |
Evershop | Evershop | 1.0.0-rc7 (including) | 1.0.0-rc7 (including) |