Business Logic Error in Macrozheng Mall Product by Macrozheng
CVE-2026-79406
5.3MEDIUM
What is CVE-2026-79406?
A security vulnerability has been identified in the macrozheng mall up to version 1.0.3. Specifically, the flaw resides in the OmsCartItemServiceImpl.updateQuantity function located in the /cart/update/quantity file. This vulnerability allows attackers to manipulate the quantity argument, potentially leading to unintended business logic errors. Remote exploitation is possible, allowing malicious actors to trigger this vulnerability without direct access to the system. The vendor has not provided clarification after removing a related issue from GitHub, raising concerns about transparency regarding the issue's resolution.
Affected Version(s)
mall 1.0.0
mall 1.0.1
mall 1.0.2
