Product
An improper authorization vulnerability in EverShop versions prior to 2.2.1 allows unauthenticated attackers to hijack customer accounts by exploiting an incorrectly configured API route.