Unknown · Macrozheng Mall · CVE-2026-15186
**Name of the Vulnerable Software and Affected Versions**
macrozheng mall versions prior to 1.0.4
**Description**
An issue exists in the Portal Endpoint component within the file `/returnApply/create`. Remote manipulation of the `orderId` variable leads to improper control of resource identifiers, which can be exploited to gain unauthorized access to resources.
**Recommendations**
Update macrozheng mall to version 1.0.4 or later.
As a temporary mitigation, restrict access to the `/returnApply/create` endpoint.