CVE-2026-108691 PUBLISHED

mall4j through 4.0 Operator Precedence Error Deletes Other Users' Cart Items via /p/shopCart/cleanExpiryProdList

Assigner: VulnCheck
Reserved: 10.10.2026 Published: 11.10.2026 Updated: 11.10.2026

mall4j through 4.0 contains an improper authorization vulnerability that allows authenticated storefront customers to delete other shoppers' cart items through an operator precedence error in the cleanExpiryProdList SQL statement. Attackers can send one DELETE request to /p/shopCart/cleanExpiryProdList to remove every user's cart entries for off-shelf products, which do not return when products are restocked.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N
CVSS Score: 5.3

Product Status

Vendor gz-yami
Product mall4j
Versions Default: unaffected
  • affected from 0 to 4.0 (incl.)

Credits

  • Yaqi Chao finder

References

Problem Types

  • Operator Precedence Logic Error CWE