VYPR

Mall4j

by Gz Yami

CVEs (4)

  • CVE-2026-102365MedSep 29, 2026
    risk 0.35cvss 6.5epss 0.00

    mall4j through 4.0 fails to enforce authorization checks on GET endpoints in UserAddrController that retrieve customer address data. Authenticated attackers can call /user/addr/page and /user/addr/info endpoints to harvest all customer addresses including names, phone numbers,…

  • CVE-2026-102364MedSep 29, 2026
    risk 0.28cvss 5.4epss 0.00

    mall4j through 4.0 fails to validate the sysType field in sa-token sessions, allowing storefront customers to authenticate as back-office users by reusing their session tokens. Attackers can register on the public storefront and use their customer session token to access admin…

  • CVE-2026-102362MedSep 29, 2026
    risk 0.27cvss 5.3epss 0.00

    mall4j through 4.0 fails to implement authentication controls on the DELETE /prodComm endpoint in ProdCommController. Unauthenticated attackers can delete arbitrary product reviews by supplying the prodCommId parameter without authorization checks.

  • CVE-2026-102363LowSep 29, 2026
    risk 0.17cvss 3.7epss 0.00

    mall4j through 4.0 contains a missing authentication vulnerability in the DeliveryController checkDelivery endpoint that allows unauthenticated attackers to read shipment tracking information by supplying an order number parameter. Attackers can access carrier names, waybill…