MEDIUM
gz-yami
CVE published 2026-10-11
CVE-2026-108691
CVE-2026-108691 is a vulnerability in mall4j through version 4.0 that allows authenticated storefront customers to delete other shoppers' cart items due to an improper authorization issue. This is caused by an operator precedence error in the cleanExpiryProdList SQL statement. An attacker can exploit this by sending a single DELETE request to /p/shopCart/cleanExpiryProdList, which can remove every user's [truncated]