Metrics
Affected Vendors & Products
Wed, 25 Mar 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 23 Mar 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mickasmt
Mickasmt next-saas-stripe-starter |
|
| Vendors & Products |
Mickasmt
Mickasmt next-saas-stripe-starter |
Sun, 22 Mar 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw has been found in mickasmt next-saas-stripe-starter 1.0.0. Affected by this issue is the function openCustomerPortal of the file actions/open-customer-portal.ts of the component Stripe API. This manipulation causes authorization bypass. Remote exploitation of the attack is possible. The complexity of an attack is rather high. The exploitation is known to be difficult. | |
| Title | mickasmt next-saas-stripe-starter Stripe API open-customer-portal.ts openCustomerPortal authorization | |
| Weaknesses | CWE-285 CWE-639 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-03-25T13:45:28.122Z
Reserved: 2026-03-21T16:49:05.353Z
Link: CVE-2026-4549
Updated: 2026-03-25T13:45:20.980Z
Status : Awaiting Analysis
Published: 2026-03-22T14:16:35.040
Modified: 2026-03-23T14:31:37.267
Link: CVE-2026-4549
No data.