mall4j 4.0 及以下版本在 UserAddrController 中,针对获取客户地址数据的 GET 端点未实施授权检查。攻击者在通过身份验证后,可以调用 /user/addr/page 和 /user/addr/info 端点,从而窃取所有客户的地址信息,包括姓名、电话号码和邮政信息。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-102361 | 9.1 CRITICAL | mall4j through 4.0 Missing Authentication in Password Update Endpoint |
| CVE-2026-102364 | 5.4 MEDIUM | mall4j through 4.0 Improper Authentication Accepts Storefront Tokens on Admin API |
| CVE-2026-102367 | 5.4 MEDIUM | mall4j through 4.0 Insufficient Session Expiration via Token Refresh |
| CVE-2026-102362 | 5.3 MEDIUM | mall4j through 4.0 Missing Authentication in Product Review Deletion |
| CVE-2026-102366 | 4.4 MEDIUM | mall4j through 4.0 Unrestricted File Upload in Admin File Endpoints |
| CVE-2026-102363 | 3.7 LOW | mall4j through 4.0 Unauthenticated Shipment Tracking Disclosure via Order Number |
No comments yet