A flaw has been found in mickasmt next-saas-stripe-starter 1.0.0. Affected by this issue is the function openCustomerPortal of the file actions/open-customer-portal.ts of the component Stripe API. This manipulation causes authorization bypass. Remote exploitation of the attack is possible. The complexity of an attack is rather high. The exploitation is known to be difficult.
Metrics
Affected Vendors & Products
References
History
Sun, 22 Mar 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw has been found in mickasmt next-saas-stripe-starter 1.0.0. Affected by this issue is the function openCustomerPortal of the file actions/open-customer-portal.ts of the component Stripe API. This manipulation causes authorization bypass. Remote exploitation of the attack is possible. The complexity of an attack is rather high. The exploitation is known to be difficult. | |
| Title | mickasmt next-saas-stripe-starter Stripe API open-customer-portal.ts openCustomerPortal authorization | |
| Weaknesses | CWE-285 CWE-639 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2026-03-22T13:47:25.406Z
Updated: 2026-03-22T13:47:25.406Z
Reserved: 2026-03-21T16:49:05.353Z
Link: CVE-2026-4549
No data.
Status : Received
Published: 2026-03-22T14:16:35.040
Modified: 2026-03-22T14:16:35.040
Link: CVE-2026-4549
No data.