CVE-2024-29888Medium· 4.2▾ SunlitSaleor: Customers' addresses leak when using Warehouse as a `Pickup: Local stock only` delivery method
▾ Sunlit zone — Low / medium · no exploitation signal
impact 23.1 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.5%
Using Pickup: Local stock only as a click-and-collect points could cause a leak of customer addresses
When using Pickup: Local stock only click-and-collect as a delivery method in specific conditions the customer could overwrite the warehouse address with its own, which exposes its address as click-and-collect address.
The vulnerability can cause the leak of customer's address when using click-and-collect delivery option marked as Local stock only. It has impact on all orders with click-and-collect delivery method marked as Pickup:Local stock only
The affected versions: >=3.14.56 <3.14.61, >=3.15.31 <3.15.37, >=3.16.27 <3.16.34, >=3.17.25 <3.17.32, >=3.18.19 <3.18.28, >=3.19.5 <3.19.15
This issue has been patched in versions: 3.14.61, 3.15.37, 3.16.34, 3.17.32, 3.18.28, 3.19.15
We strongly recommend upgrading to the latest versions, in case of inability to upgrade straight away, possible workarounds are:
Pickup option is set to Local stock only.saleor >= 3.14.56, < 3.14.61saleor >= 3.15.31, < 3.15.37saleor >= 3.16.27, < 3.16.34saleor >= 3.17.25, < 3.17.32saleor >= 3.18.19, < 3.18.28saleor >= 3.19.5, < 3.19.15Upgrade to a patched release:
saleor 3.14.61saleor 3.15.37saleor 3.16.34saleor 3.17.32saleor 3.18.28saleor 3.19.15Connected by shared product, vendor, weakness, or advisory.
CVE-2023-26051Medium· 6.5Saleor has Staff-Authenticated Error Message Information Disclosure Vulnerability via Python Exceptions
CVE-2022-0932Medium· 6.5saleor Missing Authorization vulnerability
CVE-2023-26052Low· 3.7Saleor Unauthenticated Information Disclosure Vulnerability via Python Exceptions
CVE-2020-7964Medium· 5.3Missing Authentication for Critical Function in Saleor
CVE-2019-13594High· 8.8Mirumee Saleor CSRF Protection Disabled
CVE-2026-93650Low· 3.7A vulnerability was determined in Saleor up to 3.20.118/3.21.54/3.22.47/3.23.14