5.3
CVE-2026-79406
- EPSS 0.22%
- Veröffentlicht 25.08.2026 13:19:32
- Zuletzt bearbeitet 27.08.2026 17:20:47
- Erkennungen
macrozheng mall quantity OmsCartItemServiceImpl.updateQuantity logic error
A security vulnerability has been detected in macrozheng mall up to 1.0.3. Affected is the function OmsCartItemServiceImpl.updateQuantity of the file /cart/update/quantity. The manipulation of the argument quantity leads to business logic errors. The attack may be initiated remotely. The vendor deleted the GitHub issue for this vulnerability without any explanation.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstellermacrozheng
≫
Produkt
mall
Version
1.0.0
Status
affected
Version
1.0.1
Status
affected
Version
1.0.2
Status
affected
Version
1.0.3
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.22% | 0.129 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| cna@vuldb.com | 5.3 | 0 | 0 |
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
| cna@vuldb.com | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
|
| cna@vuldb.com | 4 | 8 | 2.9 |
AV:N/AC:L/Au:S/C:N/I:P/A:N
|
https://github.com/macrozheng/mall/
https://github.com/macrozheng/mall/issues/984
https://vuldb.com/cve/CVE-2026-79406
https://vuldb.com/submit/886961
https://vuldb.com/vuln/394944
https://vuldb.com/vuln/394944/cti