PT-2026-22209 · Evershop · Evershop

·

CVE-2026-28213

·

Publicado

2026-02-26

·

Atualizado

2026-03-03

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions EverShop versions prior to 2.1.1
Description EverShop, a TypeScript-first eCommerce platform, has an issue in the "Forgot Password" functionality. When a target email address is provided, the API response includes the password reset token. This allows an attacker to take over the associated account. The password reset token is intended to be a secret string used to verify the user's identity.
Recommendations Update to version 2.1.1 or later.

Exploit

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-28213
GHSA-CG73-G723-39JW

Produtos afetados

Evershop