CVE-2026-108690 PUBLISHED

mall4j through 4.0 Operator Precedence Error Exposes Other Users' Cart Items via /p/shopCart/expiryProdList

Assigner: VulnCheck
Reserved: 10.10.2026 Published: 11.10.2026 Updated: 11.10.2026

mall4j through 4.0 contains an information disclosure vulnerability that allows authenticated customers to read other shoppers' cart items due to an operator precedence error in the getShopCartExpiryItems SQL filter. Attackers with any storefront account can request GET /p/shopCart/expiryProdList to retrieve off-shelf product basket entries including product, SKU, quantity, shop, and promoter card numbers.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 5.3

Product Status

Vendor gz-yami
Product mall4j
Versions Default: unaffected
  • affected from 0 to 4.0 (incl.)

Credits

  • Yaqi Chao finder

References

Problem Types

  • Operator Precedence Logic Error CWE