Saleor is an e-commerce platform that serves high-volume companies. When using Pickup: Local stock only click-and-collect as a delivery method in specific conditions the customer could overwrite the warehouse address with its own, which exposes its address as click-and-collect address. This issue has been patched in versions: 3.14.61, 3.15.37, 3.16.34, 3.17.32, 3.18.28, 3.19.15.
{
"cwe_ids": [
"CWE-359"
],
"cna_assigner": "GitHub_M",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/29xxx/CVE-2024-29888.json"
}{
"cpe": "cpe:2.3:a:saleor:saleor:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "3.14.56"
},
{
"fixed": "3.14.61"
},
{
"introduced": "3.15.31"
},
{
"fixed": "3.15.37"
},
{
"introduced": "3.16.27"
},
{
"fixed": "3.16.34"
},
{
"introduced": "3.17.25"
},
{
"fixed": "3.17.32"
},
{
"introduced": "3.18.19"
},
{
"fixed": "3.18.28"
},
{
"introduced": "3.19.5"
},
{
"fixed": "3.19.15"
}
],
"source": [
"CPE_RANGE",
"REFERENCES"
]
}