Missing Authentication in Ecommerce Template's Checkout Functionality by MarcosCamara01
CVE-2026-90896

8.2HIGH

Key Information:

Vendor
CVE Published:
14 September 2026

What is CVE-2026-90896?

The Ecommerce Template developed by MarcosCamara01 has a vulnerability in its checkout session lookup handler that allows unauthorized users to access sensitive buyer information. Specifically, the absence of session ownership verification allows attackers with a valid Stripe Checkout Session ID to retrieve details such as the buyer's personal information, including name, email, phone number, address, and the amount paid. This information is exposed via the GET handler without appropriate authentication checks, creating a significant risk of data leakage. The session_id can also be inadvertently disclosed through various means such as browser URL leakage, Referer headers, and server logs, further increasing the potential impact on buyers.

Affected Version(s)

Ecommerce Template 0 < 91e273c

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jaime Ramirez
Dario Rivas Quero
Secur0 CNA
.