PT-2026-102410 · Mall4J · Mall4J
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
mall4j versions prior to 4.1
Description
An insufficient session expiration issue exists in the token refresh mechanism. The system fails to validate the enabled flag when issuing new sessions, allowing disabled user accounts to indefinitely renew their sessions via the 'POST /token/refresh' endpoint. This allows users to retain access to the system even after their accounts have been disabled.
Recommendations
Update mall4j to a version later than 4.0.
As a temporary workaround, restrict access to the 'POST /token/refresh' endpoint for accounts that have been marked as disabled.
Exploit
Fix
Insufficient Session Expiration
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mall4J