PT-2026-91735 · Unknown · Marcoscamara01 Ecommerce Template
CVSS v4.0
8.2
High
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
MarcosCamara01 Ecommerce Template versions prior to commit 91e273c
Description
Missing authentication in the checkout session lookup handler allows a remote, unauthenticated attacker to retrieve full session objects. By providing a valid Stripe Checkout Session ID, an attacker can access sensitive buyer information, including name, email, phone number, billing address, amount paid, and internal
userId. This occurs because the GET handler calls the stripe.checkout.sessions.retrieve() function and returns the data without verifying the user's authentication or ownership of the session. The session ID is often exposed in the browser URL after payment, making it susceptible to leakage via Referer headers, analytics tools, server access logs, and browser history. The affected API endpoint is GET '/api/stripe/checkout sessions'.Recommendations
Update MarcosCamara01 Ecommerce Template to commit 91e273c or later.
As a temporary workaround, restrict access to the GET '/api/stripe/checkout sessions' endpoint to ensure only authenticated users can access it.
Exploit
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Marcoscamara01 Ecommerce Template