Payment Status Endpoint Vulnerability in macrozheng mall by macrozheng
CVE-2026-82423

5.3MEDIUM

Key Information:

Vendor

Macrozheng

Status
Vendor
CVE Published:
29 August 2026

What is CVE-2026-82423?

A vulnerability exists in the macrozheng mall's Payment Status Endpoint affecting versions up to 1.0.3. The flaw is due to improper handling of the 'orderId' parameter within the '/order/paySuccess' function. This weakness allows attackers to manipulate the order processing behavior, potentially leading to unauthorized alterations in the payment workflow. Notably, this type of attack can be executed remotely, raising significant security concerns. The vendor has removed a GitHub issue related to this vulnerability, leaving users without clear guidance on the risk.

Affected Version(s)

mall 1.0.0

mall 1.0.1

mall 1.0.2

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

peanutbutter (VulDB User)
VulDB CNA Team
.