Impact
An authenticated admin‑panel user can adjust inventory levels for any product variant without the required edit_product_variants authorization. The VariantStock component exposes the stockAction method without access control and the $variant property is not locked, allowing the page to modify it. This means staff with only browse_products permission can inflate stock, reduce stock, or force out‑of‑stock states for variants that are not visible on the current page. The weakness is a Broken Access Control flaw (CWE‑862), resulting in integrity violations and business impact through inaccurate inventory counts.
Affected Systems
Shopper Labs’ Shopper e‑commerce admin panel, versions earlier than 2.9.2. The vulnerability was fixed in release 2.9.2.
Risk and Exploitability
With a CVSS score of 8.1 the vulnerability is considered high severity. The EPSS score is < 1%, indicating a very low exploitation probability, and it is not listed in CISA KEV. The vulnerability can be exploited by any authenticated admin user with Browse‑Products permissions within the admin interface. An attacker can irregularly increase or decrease stock levels, leading to false inventory availability and associated financial loss.
OpenCVE Enrichment
Github GHSA