CVE-2023-26051Medium· 6.5▾ SunlitSaleor has Staff-Authenticated Error Message Information Disclosure Vulnerability via Python Exceptions
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.8%
0.8% → 0.8%
Some internal Python exceptions are not handled properly and thus are returned in API as error messages. Some messages might contain sensitive information like user email address in staff-authenticated requests.
This issue has been patched in versions 3.1.48, 3.7.59, 3.8.30, 3.9.27, 3.10.14 and 3.11.12.
None
If you have any questions or comments about this advisory:
saleor >= 2.0.0, < 3.1.48saleor >= 3.11.0, < 3.11.12saleor >= 3.10.0, < 3.10.14saleor >= 3.9.0, < 3.9.27saleor >= 3.8.0, < 3.8.30saleor >= 3.7.0, < 3.7.59Upgrade to a patched release:
saleor 3.1.48saleor 3.11.12saleor 3.10.14saleor 3.9.27saleor 3.8.30saleor 3.7.59Connected by shared product, vendor, weakness, or advisory.
CVE-2023-26052Low· 3.7Saleor Unauthenticated Information Disclosure Vulnerability via Python Exceptions
CVE-2024-29888Medium· 4.2Saleor: Customers' addresses leak when using Warehouse as a `Pickup: Local stock only` delivery method
CVE-2022-0932Medium· 6.5saleor Missing Authorization vulnerability
CVE-2020-7964Medium· 5.3Missing Authentication for Critical Function in Saleor
CVE-2019-13594High· 8.8Mirumee Saleor CSRF Protection Disabled
CVE-2026-93650Low· 3.7A vulnerability was determined in Saleor up to 3.20.118/3.21.54/3.22.47/3.23.14