Skip to content

[Security] Missing authorization in customer API + SSRF — EverShop <= v2.1.2 #941

Description

@iaohkut

[Security] Missing Authorization in Customer API + SSRF in Image Processor (v2.1.2)

Note: Full exploit details withheld from public report. Contact: thb2601@gmail.com

Affected Version

EverShop <= v2.1.2

Vulnerabilities Found

1. Unauthenticated Account Takeover — PATCH /api/customers/:id (Critical · CWE-862 · CVSS 9.1)
Route is access:"public", auth middleware skips. Handler has no ownership check.
Any caller with a customer UUID can overwrite their email and password.
File: modules/customer/api/updateCustomer/updateCustomer.js

2. IDOR — Customer Address Endpoints (High · CWE-639 · CVSS 7.5)
POST/PATCH/DELETE /customers/:customer_id/addresses — same access:"public" + no ownership check.
Any caller can create, modify, or delete any customer's addresses without authentication.
Files: createCustomerAddress.js, updateCustomerAddress.js, deleteCustomerAddress.js

3. SSRF — GET /images?src= (High · CWE-918 · CVSS 8.6)
Image processor fetches any external URL without IP validation.
Enables requests to internal services and cloud metadata (AWS IMDSv1 169.254.169.254).
File: modules/cms/services/imageProcessor.ts

Fix Available

https://github.com/iaohkut/evershop-old/tree/fix/missing-auth-customer-api

Disclosure Timeline

  • 2026-06-03: Confirmed dynamically on v2.1.2
  • 2026-09-01: 90-day public disclosure deadline

Please acknowledge at thb2601@gmail.com for full technical details.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions