VDB
Sign up
CRITICAL9.8

GHSA-5mmr-9qx3-3pf9

Code execution in evershop

Quick fix

GHSA-5mmr-9qx3-3pf9 — @evershop/evershop: upgrade to the fixed version with the command below.

npm install @evershop/evershop@1.0.0-rc.8

Details

An issue in EverShop NPM versions before v.1.0.0-rc.8 allows a remote attacker to obtain sensitive information and execute arbitrary code via the /deleteCustomer/route.json file.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/@evershop/evershop
Introduced in: 0Fixed in: 1.0.0-rc.8
Fixnpm install @evershop/evershop@1.0.0-rc.8

References