@evershop/evershop is vulnerable to Exposure of Sensitive Information
98
Critical Risk
The customer forgot-password API returns the generated password reset token directly in its HTTP response when a target email address is supplied. Because the token is disclosed to the requester, a request can be made for another customer's email, the token read from the response, and a new password set for that account. The fix stops returning the reset token in the API response.
You are affected if you are using a version that falls within the vulnerable range.
@evershop/evershop is vulnerable to Exposure of Sensitive Information in versions 0.0.1 - 2.1.0.
Upgrade the @evershop/evershop library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.