rootpwn

high · CVSS v3 6.5 · CVSS v4 7.1

CVE-2026-102365

mall4j through 4.0 fails to enforce authorization checks on GET endpoints in UserAddrController that retrieve customer a…

Description

mall4j through 4.0 fails to enforce authorization checks on GET endpoints in UserAddrController that retrieve customer address data. Authenticated attackers can call /user/addr/page and /user/addr/info endpoints to harvest all customer addresses including names, phone numbers, and postal information.

Scores

Severity
high
CVSS v2
6.8
CVSS v3
6.5
CVSS v4
7.1
EPSS
—

← All CVEs