Impact
Shopper, a headless e-commerce admin panel, contained a server‑side authorization only browse permissions could invoke mass delete operations for attributes and tags or toggle the enabled state of attributes, brands, categories, and suppliers. These actions could break product variants and severely disrupt storefront catalog visibility.
Affected Systems
The vulnerability affects Shopper Labs’ Shopper product versions less than 2.9.2. The issue was fixed in version 2.9.2, which applies the missing authorization checks.
Risk and Exploitability
The vulnerability has a CVSS score of 8.1, indicating high severity. The EPSS score is < 1%, and the issue is not listed in CISA KEV. The lack of server‑side checks allows staff with only browse permissions to perform privileged bulk actions. Based on the description, the likely attack vector is the administrative interface accessed by staff accounts; no external attack vector is documented.
OpenCVE Enrichment
Github GHSA