Payment Status Endpoint Vulnerability in macrozheng mall by macrozheng
CVE-2026-82423
5.3MEDIUM
What is CVE-2026-82423?
A vulnerability exists in the macrozheng mall's Payment Status Endpoint affecting versions up to 1.0.3. The flaw is due to improper handling of the 'orderId' parameter within the '/order/paySuccess' function. This weakness allows attackers to manipulate the order processing behavior, potentially leading to unauthorized alterations in the payment workflow. Notably, this type of attack can be executed remotely, raising significant security concerns. The vendor has removed a GitHub issue related to this vulnerability, leaving users without clear guidance on the risk.
Affected Version(s)
mall 1.0.0
mall 1.0.1
mall 1.0.2
