Mirumee develops Saleor, an open-source e-commerce platform, with a durable signal centered on application-layer security issues including cleartext storage of sensitive information, cross-site request forgery, and missing authentication and authorization controls for critical functions. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mirumee over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-13594HIGH In Mirumee Saleor 2.7.0 (fixed in 2.8.0), CSRF protection middleware was accidentally disabled, which allowed attackers to send a POST request without a valid CSRF token and be acc | Jul 14, 2019 | 8.8 | 27 | NO | NO |
CVE-2019-1010304MEDIUM Saleor Issue was introduced by merge commit: e1b01bad0703afd08d297ed3f1f472248312cc9c. This commit was released as part of 2.0.0 release is affected by: Incorrect Access Control. T | Jul 15, 2019 | 5.3 | 19 | NO | NO |
CVE-2020-15085MEDIUM In Saleor Storefront before version 2.10.3, request data used to authenticate customers was inadvertently cached in the browser's local storage mechanism, including credentials. A | Jun 30, 2020 | 6.1 | 17 | NO | NO |
CVE-2020-7964MEDIUM An issue was discovered in Mirumee Saleor 2.x before 2.9.1. Incorrect access control in the checkoutCustomerAttach mutations allows attackers to attach their checkouts to any user | Jan 24, 2020 | 5.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mirumee.
Media articles that mention a CVE ID that affects a product developed by Mirumee — matched by CVE ID, not by vendor name.