Maze Code found an account takeover bug in Saleor
ID: e74aaed6-3a1e-5a78-9f51-901ecbc40f1c
STIX ID: report--e74aaed6-3a1e-5a78-9f51-901ecbc40f1c
Feed Name: Maze Blog
Threat Score
Maze Code reported a logic vulnerability in Saleor where an attacker can pre-register accounts using victims' emails and, if the victim clicks the routine confirmation link, cause guest orders and gift cards to be merged into the attacker-controlled account; the flaw affects default email-confirmation flows in several Saleor 3.21–3.23 versions, is trivially automatable at scale, and has been fixed in the patched releases (3.21.67, 3.22.63, 3.23.22, and 3.24 with additional safeguards).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
