coreshop/core-shop is vulnerable to Generation of Error Message Containing Sensitive Information
19
Low Risk
Affected versions of this package are vulnerable to sensitive information exposure through error responses in the OrderInvoiceController and OrderShipmentController. In the event of a server error, detailed exception messages and full stack traces were previously returned directly to clients, potentially revealing internal implementation details such as class names, file paths, or control flow. This can aid attackers in reconnoitering the application and crafting further attacks.
You are affected if you are using a version that falls within the vulnerable range.
coreshop/core-shop is vulnerable to Generation of Error Message Containing Sensitive Information in versions 2.0.0 - 4.1.9.
Upgrade the coreshop/core-shop library to a patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant