PT-2026-91735 · Unknown · Marcoscamara01 Ecommerce Template

·

CVE-2026-90896

·

Published

2026-09-14

·

Updated

2026-09-15

CVSS v4.0

8.2

High

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions MarcosCamara01 Ecommerce Template versions prior to commit 91e273c
Description Missing authentication in the checkout session lookup handler allows a remote, unauthenticated attacker to retrieve full session objects. By providing a valid Stripe Checkout Session ID, an attacker can access sensitive buyer information, including name, email, phone number, billing address, amount paid, and internal userId. This occurs because the GET handler calls the stripe.checkout.sessions.retrieve() function and returns the data without verifying the user's authentication or ownership of the session. The session ID is often exposed in the browser URL after payment, making it susceptible to leakage via Referer headers, analytics tools, server access logs, and browser history. The affected API endpoint is GET '/api/stripe/checkout sessions'.
Recommendations Update MarcosCamara01 Ecommerce Template to commit 91e273c or later. As a temporary workaround, restrict access to the GET '/api/stripe/checkout sessions' endpoint to ensure only authenticated users can access it.

Exploit

Fix

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-90896

Affected Products

Marcoscamara01 Ecommerce Template