Retour à la veille

CVE-2026-102365

Publié : 29 septembre 2026
Modifié : 29 septembre 2026
Lien officiel NVD
Score CVSS
6.5
MEDIUM

Description détaillée

mall4j through 4.0 fails to enforce authorization checks on GET endpoints in UserAddrController that retrieve customer address data. Authenticated attackers can call /user/addr/page and /user/addr/info endpoints to harvest all customer addresses including names, phone numbers, and postal information.

Vecteur d'attaque (CVSS)

Vecteur brut :CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Références et Patchs