Business Logic Error in Macrozheng Mall Product by Macrozheng
CVE-2026-79406

5.3MEDIUM

Key Information:

Vendor

Macrozheng

Status
Vendor
CVE Published:
25 August 2026

What is CVE-2026-79406?

A security vulnerability has been identified in the macrozheng mall up to version 1.0.3. Specifically, the flaw resides in the OmsCartItemServiceImpl.updateQuantity function located in the /cart/update/quantity file. This vulnerability allows attackers to manipulate the quantity argument, potentially leading to unintended business logic errors. Remote exploitation is possible, allowing malicious actors to trigger this vulnerability without direct access to the system. The vendor has not provided clarification after removing a related issue from GitHub, raising concerns about transparency regarding the issue's resolution.

Affected Version(s)

mall 1.0.0

mall 1.0.1

mall 1.0.2

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

peanutbutter (VulDB User)
VulDB CNA Team
.