{"id":"CVE-2019-13594","details":"In Mirumee Saleor 2.7.0 (fixed in 2.8.0), CSRF protection middleware was accidentally disabled, which allowed attackers to send a POST request without a valid CSRF token and be accepted by the server.","aliases":["GHSA-fgjh-x3f8-8gmh","PYSEC-2026-916"],"modified":"2026-08-27T08:15:20.584786Z","published":"2019-07-14T17:15:11.243Z","references":[{"type":"ADVISORY","url":"https://github.com/mirumee/saleor/releases/tag/2.8.0"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/saleor/saleor","events":[{"introduced":"a86f6219b822b82feebe71adb6cfddd6640f8489"},{"last_affected":"a86f6219b822b82feebe71adb6cfddd6640f8489"},{"fixed":"e0f08e7b5b2f49e270c16252c837419721aa4cc6"}],"database_specific":{"cpe":"cpe:2.3:a:mirumee:saleor:2.7.0:*:*:*:*:*:*:*","extracted_events":[{"introduced":"2.7.0"},{"last_affected":"2.7.0"}],"source":["CPE_STRING","REFERENCES"]}}],"versions":["2.7.0","demo/2.7.0b1","demo/2.7.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-13594.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}