kyon147/laravel-shopify is vulnerable to Information Disclosure
73
High Risk
Affected versions of this package are vulnerable to information disclosure due to improper access control in API routes protected by the VerifyShopify middleware. Any store can access data belonging to another store by appending a shop GET parameter with the target store's domain to an API request, bypassing authorization checks and exposing sensitive data.
You are affected if you are using a version that falls within the vulnerable range.
kyon147/laravel-shopify is vulnerable to Information Disclosure in versions 17.3.3 - 23.0.0.
Upgrade the kyon147/laravel-shopify library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant