PT-2026-102406 · Mall4J · Mall4J
CVSS v4.0
6.3
Medium
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
mall4j versions prior to 4.1
Description
A missing authentication issue exists in the
DeliveryController checkDelivery endpoint. This allows unauthenticated attackers to retrieve shipment tracking information, including carrier names, waybill numbers, and complete logistics trails for any order, by providing the order number parameter without ownership verification.Recommendations
Update mall4j to a version later than 4.0.
As a temporary workaround, restrict access to the
checkDelivery endpoint in the DeliveryController to minimize the risk of unauthorized data disclosure.Exploit
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mall4J