logo

Shopper Laravel Flaw Exploit Sparks Urgent E-Commerce Security Warning

ID: cdccd8bc-b54d-5738-8895-1136f71ae848

STIX ID: report--cdccd8bc-b54d-5738-8895-1136f71ae848

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-06-08

Date Updated: 2026-06-08

Author: Do Son

...
...

**Executive summary:** A critical authorization bypass (CVE-2026-47744, CVSS 9.9) in the Shopper Laravel admin panel allows authenticated low‑privilege users to access restricted team settings, create roles, delete administrators, and grant themselves administrative permissions; upgrade to shopper/admin v2.8.0 (e.g., `composer require shopper/admin:^2.8`) immediately to apply the patch.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.