mall4j 4.0 及之前版本在令牌刷新接口(token refresh endpoint)中存在会话过期控制不足漏洞。该漏洞在处理新会话时未能验证“启用”(enabled)标志。因此,已被禁用的用户账户可通过 POST /token/refresh 接口无限期地刷新其会话,从而维持原本应被移除的访问权限。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-102361 | 9.1 CRITICAL | mall4j through 4.0 Missing Authentication in Password Update Endpoint |
| CVE-2026-102365 | 6.5 MEDIUM | mall4j through 4.0 Missing Authorization in Admin User Address Endpoints |
| CVE-2026-102364 | 5.4 MEDIUM | mall4j through 4.0 Improper Authentication Accepts Storefront Tokens on Admin API |
| CVE-2026-102362 | 5.3 MEDIUM | mall4j through 4.0 Missing Authentication in Product Review Deletion |
| CVE-2026-102366 | 4.4 MEDIUM | mall4j through 4.0 Unrestricted File Upload in Admin File Endpoints |
| CVE-2026-102363 | 3.7 LOW | mall4j through 4.0 Unauthenticated Shipment Tracking Disclosure via Order Number |
No comments yet