Shopizer
cpe:2.3:a:shopizer:shopizer:*:*:*:*:*:*:*
- 3.2.7
A vulnerability in Shopizer version 3.2.7 exists due to the server's Cross-Origin Resource Sharing (CORS) implementation, which reflects the client-supplied Origin header directly into the Access-Control-Allow-Origin response header without any validation against a whitelist. Additionally, the server allows Access-Control-Allow-Credentials: true, enabling any malicious origin to make authenticated cross-origin requests and access sensitive responses.
Exploitation of this vulnerability could lead to unauthorized access to sensitive information by allowing malicious origins to make authenticated requests and read protected data.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.