{"id":"CVE-2019-13594","details":"In Mirumee Saleor 2.7.0 (fixed in 2.8.0), CSRF protection middleware was accidentally disabled, which allowed attackers to send a POST request without a valid CSRF token and be accepted by the server.","aliases":["GHSA-fgjh-x3f8-8gmh","PYSEC-2026-916"],"modified":"2026-07-07T11:56:28.216775388Z","published":"2019-07-14T17:15:11.243Z","database_specific":{"unresolved_ranges":[{"vendor_product":"mirumee:saleor","cpes":["cpe:2.3:a:mirumee:saleor:2.7.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"2.7.0"},{"last_affected":"2.7.0"},{"introduced":"2.7.0"},{"last_affected":"2.7.0"}],"source":"CPE_STRING"}]},"references":[{"type":"ADVISORY","url":"https://github.com/mirumee/saleor/releases/tag/2.8.0"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/saleor/saleor","events":[{"introduced":"0"},{"fixed":"e0f08e7b5b2f49e270c16252c837419721aa4cc6"}],"database_specific":{"source":"REFERENCES"}}],"versions":["demo/2.7.0b1","demo/2.7.0","demo/2.6.0b1","demo/2.6.0","demo/2.5.0","demo/2.4.0","demo/2.3.0b3","demo/2.3.0b2","demo/2.3.0b1","demo/2.2.0b2","demo/2.2.0b1","demo/2.2.0","demo/2.1.0b1","demo/2.0.0b5","demo/2.0.0b4","demo/2.0.0b3","demo/2.0.0b2","demo/2.0.0","demo/v2018.09","demo/v2018.08","demo/v2018.06.10","demo/v2018.06.9","demo/v2018.06.8","demo/v2018.06.7","demo/v2018.06.6","demo/v2018.06.5","demo/v2018.06.4","demo/v2018.06.3","demo/v2018.06.2","demo/v2018.06.1","demo/v2018.06","demo/v2018.05.1","demo/v2018.05","demo/v2018.04.2","demo/v2018.04.1","demo/v2018.04","demo/v2018.03.1","demo/v2018.03","v2018.02","demo/v2018.02","v2018.01","v2017.12.1","v2017.12","v2017.11","v2017.10","v2017.09","v2017.07.0","v2017.03.4","v2017.03.3","v2017.03.2","v2017.03.1","v2017.03.0","v2017.02.1","v2017.02.0","v2016.07.0"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-13594.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}