Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-g3f9-g5vj-p62f | Shopper: Unauthorized inventory stock manipulation via unlocked variant property in VariantStock component |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 15 Sep 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 15 Sep 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Shopperlabs
Shopperlabs shopper |
|
| Vendors & Products |
Shopperlabs
Shopperlabs shopper |
Tue, 15 Sep 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.2, packages/admin/src/Livewire/Components/Products/VariantStock.php exposes stockAction() without edit_product_variants authorization and leaves public $variant client mutable because it lacks the Livewire Locked attribute. Any authenticated admin-panel user, including staff with only browse_products, can select an arbitrary product variant and inventory location through component state, then submit a positive or negative quantity adjustment. This permits browse-only staff to inflate stock, reduce stock, or force out-of-stock states for variants outside the current page. This issue is fixed in version 2.9.2. | |
| Title | Shopper: Unauthorized inventory stock manipulation via unlocked variant property in VariantStock component | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-15T19:04:52.685Z
Reserved: 2026-06-23T14:55:09.117Z
Link: CVE-2026-56829
Updated: 2026-09-15T19:04:39.903Z
Status : Received
Published: 2026-09-15T18:17:24.957
Modified: 2026-09-15T19:17:23.530
Link: CVE-2026-56829
No data.
OpenCVE Enrichment
Updated: 2026-09-15T18:45:18Z
Github GHSA