Low severity3.7NVD Advisory· Published Sep 29, 2026
CVE-2026-102363
CVE-2026-102363
Description
mall4j through 4.0 contains a missing authentication vulnerability in the DeliveryController checkDelivery endpoint that allows unauthenticated attackers to read shipment tracking information by supplying an order number parameter. Attackers can access carrier names, waybill numbers, and complete logistics trails for any order without authentication or ownership verification.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2Patches
Vulnerability mechanics
References
3- github.com/LinYuanyi1/cve-request-poc/blob/114b3f0d149e50a7678f591bf8043399fc9ac96c/mall4j/A08_delivery_check_anonymous.pynvd
- github.com/gz-yami/mall4j/blob/ffc672fc1aa4320ce02d0b93853bb456ae0a4dae/yami-shop-api/src/main/java/com/yami/shop/api/controller/DeliveryController.javanvd
- www.vulncheck.com/advisories/mall4j-through-4.0-unauthenticated-shipment-tracking-disclosure-via-order-numbernvd
News mentions
0No linked articles in our index yet.