Description
Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, three related defects on admin Livewire components allowed data tampering, sensitive data disclosure, and stored XSS. First, several Livewire components in the admin panel exposed Eloquent model identifiers as public properties without the `#[Locked]` attribute. An authenticated user could rewrite the wire payload from the browser to target any record id, bypassing the implicit scoping enforced by the page routing. Second, `Customers/Create::store()` re-passed a `Hidden` `_password` form field straight into the create payload. The plaintext password was rendered into the HTML and transported through the Livewire snapshot in clear text, exposing credentials in the page DOM and in any logging that captures Livewire payloads. Finally, the product barcode field was rendered through `DNS1DFacade::getBarcodeHTML()` with `{!! !!}`. An attacker with `edit_products` permission could persist malicious payload in the barcode field that would execute in the browser of any admin user viewing that product, enabling session theft and privileged-action chaining. Starting in v2.8.0, all vulnerable Livewire model identifiers are now marked `#[Locked]`; `Customers/Create` no longer round-trips the password through a Hidden form field; the plaintext password is hashed at action boundary and never returned to the client; and the product barcode rendering now escapes the value before passing it to the barcode generator and the output is wrapped in an `<svg>` context that does not interpret event handlers. No known workarounds are available.
Published: 2026-07-23
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Shopper is a head‑less e‑commerce admin panel that, before version 2.8.0, had three related defects in its Livewire components. First, several admin components exposed Eloquent model identifiers as public properties without the #[Locked] attribute, letting authenticated users rewrite the Livewire payload to target arbitrary record IDs and bypass the routing‑based scoping, thereby allowing data tampering and unintended data disclosure. Second, the Customers/Create::store() endpoint forwarded a hidden _password form field straight into the payload; the clear‑text password was rendered into the HTML and sent back in the Livewire snapshot, exposing credentials in the page DOM and in any server logs that capture the snapshot. Third, the product barcode field was rendered by DNS1DFacade::getBarcodeHTML() using raw {!! !!} syntax; an admin with edit_products permission could persist malicious payload in the barcode value that would execute in the browser of any admin viewing that product, causing stored XSS and enabling session theft and privilege escalation. Starting in v2.8.0, the Livewire model identifiers are locked, the password round‑tripping is removed and the plaintext password is hashed before response, and the barcode content is escaped before being passed to the generator and wrapped in an SVG context that does not interpret event handlers. These issues are classified as CWE‑200, CWE‑639, and CWE‑79.

Affected Systems

Shopper Labs’ Shopper product. Versions prior to 2.8.0 are affected; all releases 2.8.0 and later contain mitigations that lock Livewire model identifiers, remove plaintext credential round‑tripping, and escape barcode content.

Risk and Exploitability

The flaw carries a CVSS score of 8.7, indicating high severity. The EPSS score is below 1%, suggesting a low but non‑zero probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. An attacker would need a valid authenticated session in the admin interface and, for the XSS component, the edit_products permission. By forging Livewire requests or inserting malicious content into the barcode field, a threat actor could tamper with data records, exfiltrate sensitive information, or persist malicious scripts across admin sessions, effectively achieving session theft and privilege escalation. The mitigations deployed in v2.8.0 prevent these attack paths by restricting identifier access, eliminating plaintext credential round‑tripping, and escaping user data in barcode rendering.

Generated by OpenCVE AI on August 3, 2026 at 21:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Shopper to version 2.8.0 or later to apply the security fixes that lock Livewire model identifiers (mitigating CWE‑200 and CWE‑639), hash passwords before response (addressing CWE‑200), and escape barcode content (preventing CWE‑79 stored XSS).
  • Restrict the `edit_products` permission to trusted users only, or disable the barcode field for those who do not need it, to reduce the attack surface for the CWE‑79 stored XSS vulnerability.
  • Monitor Livewire request logs for unexpected model identifiers or suspicious payloads that could indicate attempts to tamper with data (CWE‑639) or inject scripts (CWE‑79).

Generated by OpenCVE AI on August 3, 2026 at 21:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-hr9v-r8r2-hg7j Shopper: Multiple data integrity and disclosure issues in admin Livewire components
History

Fri, 24 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
First Time appeared Shopperlabs
Shopperlabs shopper
Vendors & Products Shopperlabs
Shopperlabs shopper

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, three related defects on admin Livewire components allowed data tampering, sensitive data disclosure, and stored XSS. First, several Livewire components in the admin panel exposed Eloquent model identifiers as public properties without the `#[Locked]` attribute. An authenticated user could rewrite the wire payload from the browser to target any record id, bypassing the implicit scoping enforced by the page routing. Second, `Customers/Create::store()` re-passed a `Hidden` `_password` form field straight into the create payload. The plaintext password was rendered into the HTML and transported through the Livewire snapshot in clear text, exposing credentials in the page DOM and in any logging that captures Livewire payloads. Finally, the product barcode field was rendered through `DNS1DFacade::getBarcodeHTML()` with `{!! !!}`. An attacker with `edit_products` permission could persist malicious payload in the barcode field that would execute in the browser of any admin user viewing that product, enabling session theft and privileged-action chaining. Starting in v2.8.0, all vulnerable Livewire model identifiers are now marked `#[Locked]`; `Customers/Create` no longer round-trips the password through a Hidden form field; the plaintext password is hashed at action boundary and never returned to the client; and the product barcode rendering now escapes the value before passing it to the barcode generator and the output is wrapped in an `<svg>` context that does not interpret event handlers. No known workarounds are available.
Title Shopper: Multiple data integrity and disclosure issues in admin Livewire components
Weaknesses CWE-200
CWE-639
CWE-79
References
Metrics cvssV3_1

{'score': 8.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Subscriptions

Shopperlabs Shopper
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-07-23T18:19:03.439Z

Reserved: 2026-05-19T22:16:39.504Z

Link: CVE-2026-47743

cve-icon Vulnrichment

Updated: 2026-07-23T18:18:59.503Z

cve-icon NVD

Status : Deferred

Published: 2026-07-23T18:16:53.490

Modified: 2026-07-23T19:16:54.323

Link: CVE-2026-47743

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T21:15:04Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-639

    Authorization Bypass Through User-Controlled Key

  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')