Lack of authentication in NPM's package @evershop/evershop before version 1.0.0-rc.8, allows remote attackers to obtain sensitive information via improper authorization in GraphQL endpoints.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| @evershop/evershop(npm) | 0 | 1.0.0-rc.9 | N/A |
CVSS Metrics