GHSA-h4mp-g9c6-xwph
Shopper: Missing authorization on Product admin Livewire sub-form components
Quick fix
GHSA-h4mp-g9c6-xwph — shopper/framework: upgrade to the fixed version with the command below.
composer require shopper/framework:^2.8.0Details
## Impact
Sub-form Livewire components used in the product editor (`Edit`, `Inventory`, `Seo`, `Shipping`, `Files`) had no authorization on their `store()` method. Any authenticated panel user, regardless of role, could mutate any product's pricing, stock, SEO metadata, shipping dimensions, and attached media without holding `edit_products`.
The affected components accepted the product ID as a public Livewire property without `#[Locked]`, so an attacker could also target an arbitrary product by tampering with the wire payload from the client.
## Patches
Fixed in `v2.8.0`. Each sub-form `store()` now authorizes against `edit_products` and the product binding is locked.
Upgrade via:
```bash composer require shopper/admin:^2.8 ```
## Workarounds
None. Upgrade to `v2.8.0`.
## References
- Pull request: https://github.com/shopperlabs/shopper/pull/511 - CWE-862 Missing Authorization
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 2.8.0composer require shopper/framework:^2.8.0