Lack of authentication in NPM's package @evershop/evershop before version 1.0.0-rc.9, allows remote attackers to obtain sensitive information via improper authorization in GraphQL endpoints.
{ "nvd_published_at": "2024-01-13T02:15:07Z", "cwe_ids": [ "CWE-285", "CWE-287" ], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2024-01-16T16:37:00Z" }