← العودة للجدول
CVE-2026-47743
CVE-2026-47743 — GHSA: Shopper: Multiple data integrity and disclosure issues in admin Livewire components
📅 2026-06-05
🟠 High 🔥 No GHSA APT Web CVSS 8.7

📋 الوصف الكامل

## Impact Three related defects on admin Livewire components allowed data tampering, sensitive data disclosure, and stored XSS: - **IDOR via unlocked properties.** Several Livewire components in the admin panel exposed Eloquent model identifiers as public properties without the `#[Locked]` attribute. An authenticated user could rewrite the wire payload from the browser to target any record id, b

💻 الأنظمة المتأثرة

GHSA: Shopper: Multiple

⚠️ نوع التهديد

APT

🔗 CVE ID

CVE-2026-47743

📡 المصدر

GHSA

✅ الحلول والتخفيف

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←