GHSA-fvwm-j9pj-rw38HighCVSS 5.9

Isotope eCommerce through 2.9.10 derives order identifiers from uniqid() instead of a...

Published
September 23, 2026
Last Modified
September 23, 2026

🔗 CVE IDs covered (1)

📋 Description

Isotope eCommerce through 2.9.10 derives order identifiers from uniqid() instead of a cryptographically secure source, allowing unauthenticated attackers to guess identifiers. Guest orders lack ownership verification, enabling attackers to access order details including billing address, customer information, and purchased files by supplying a guessed uid parameter.

🔗 References (7)