CVE Vulnerabilities

CVE-2025-51605

Origin Validation Error

Published: Aug 22, 2025 | Modified: Sep 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An issue was discovered in Shopizer 3.2.7. The servers CORS implementation reflects the client-supplied Origin header verbatim into Access-Control-Allow-Origin without any whitelist validation, while also enabling Access-Control-Allow-Credentials: true. This allows any malicious origin to make authenticated cross-origin requests and read sensitive responses.

Weakness

The product does not properly verify that the source of data or communication is valid.

Affected Software

Name Vendor Start Version End Version
Shopizer Shopizer 3.2.7 (including) 3.2.7 (including)

References