Shopizer CORS Vulnerability Allowing Authenticated Cross-Origin Requests in Version 3.2.7

Vulnerability

A vulnerability in Shopizer version 3.2.7 exists due to the server's Cross-Origin Resource Sharing (CORS) implementation, which reflects the client-supplied Origin header directly into the Access-Control-Allow-Origin response header without any validation against a whitelist. Additionally, the server allows Access-Control-Allow-Credentials: true, enabling any malicious origin to make authenticated cross-origin requests and access sensitive responses.

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive information by allowing malicious origins to make authenticated requests and read protected data.

Added: Aug 22, 2025, 4:24 PM
Updated: Aug 22, 2025, 6:54 PM

Vulnerability Rating

Custom Algorithm
spread
1.0
impact
2.5
exploitability
9.7
remediation
0.0
relevance
0.4
threat
6.4
urgency
2.9
incentive
10.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.