{"id":"GHSA-fgjh-x3f8-8gmh","summary":"Mirumee Saleor CSRF Protection Disabled","details":"In Mirumee Saleor 2.7.0 (fixed in 2.8.0), CSRF protection middleware was accidentally disabled, which allowed attackers to send a POST request without a valid CSRF token and be accepted by the server.","aliases":["CVE-2019-13594","PYSEC-2026-916"],"modified":"2026-07-07T11:56:28.216775388Z","published":"2022-05-24T16:50:13Z","database_specific":{"nvd_published_at":"2019-07-14T17:15:00Z","cwe_ids":["CWE-352"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2023-08-01T23:16:22Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-13594"},{"type":"WEB","url":"https://github.com/mirumee/saleor/commit/94c07034ff1bfc209461e39ca1bb6228d8ca0e35"},{"type":"WEB","url":"http://web.archive.org/web/20190713094847/https://github.com/mirumee/saleor/releases/tag/2.8.0"}],"affected":[{"package":{"name":"saleor","ecosystem":"PyPI","purl":"pkg:pypi/saleor"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.7.0"},{"fixed":"2.8.0"}]}],"versions":["2.7.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-fgjh-x3f8-8gmh/GHSA-fgjh-x3f8-8gmh.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}