Impact
Shopper, a headless e‑commerce admin panel, allows an authenticated staff user who has only browse_products permissions to call the Livewire store action for product media. Without the edit_products authorization check this action can replace the thumbnail and gallery images for a product whose Media component was initialized. The flaw is a missing authorization control (CWE‑862) that permits unauthorized modification of product assets while the product binding remains locked, limiting the effect only to products whose edit pages were already loaded.
Affected Systems
Shopper labs’ Shopper product, versions prior to 2.9.2—including 2.9.1 and earlier—are affected. The vulnerability is resolved in Shopper 2.9.2 and later releases.
Risk and Exploitability
The CVSS score of 6.5 places the flaw in the medium severity range, and the EPSS score of < 1% indicates a very low probability of exploitation in the wild. The issue is not listed in the CISA KEV catalog. Exploitation requires an authenticated staff user with browse_products permission who can access a product edit page. The impact is confined to the replacement of product thumbnail and gallery images for products whose edit page was previously loaded, rather than full administrative control, but it can still be used to deface or misrepresent products in the store.
OpenCVE Enrichment
Github GHSA