CVE-2026-82364 PUBLISHED

macrozheng mall Order Submission submit race condition

Assigner: VulDB
Reserved: 28.08.2026 Published: 29.08.2026 Updated: 29.08.2026

A security vulnerability has been detected in macrozheng mall up to 1.0.3. This impacts an unknown function of the file /order/submit of the component Order Submission. The manipulation leads to race condition. It is possible to initiate the attack remotely. The attack is considered to have high complexity. The exploitability is said to be difficult. The vendor deleted the GitHub issue for this vulnerability without and explanation.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X
CVSS Score: 2.3

Product Status

Vendor macrozheng
Product mall
Versions
  • Version 1.0.0 is affected
  • Version 1.0.1 is affected
  • Version 1.0.2 is affected
  • Version 1.0.3 is affected

Credits

  • peanutbutter (VulDB User) reporter
  • VulDB CNA Team coordinator

References

Problem Types

  • Race Condition CWE