rootpwn

medium · CVSS v3 5.3 · CVSS v4 6.9

CVE-2026-102362

mall4j through 4.0 fails to implement authentication controls on the DELETE /prodComm endpoint in ProdCommController. Un…

Description

mall4j through 4.0 fails to implement authentication controls on the DELETE /prodComm endpoint in ProdCommController. Unauthenticated attackers can delete arbitrary product reviews by supplying the prodCommId parameter without authorization checks.

Scores

Severity
medium
CVSS v2
5
CVSS v3
5.3
CVSS v4
6.9
EPSS
—

← All CVEs