Impact
The vulnerability is a missing authentication in the PUT /user/updatePwd endpoint; attackers can supply a target username in the request body and reset passwords without verification. This allows account takeover, providing attackers with access to orders, personal data, and other sensitive information. The weakness corresponds to CWE-306.
Affected Systems
The affected product is GZ‑Yami’s mall4j, versions 4.0 and earlier. Any installation that has not applied updates to add authentication to the password update endpoint is vulnerable. The vulnerability is listed for all mall4j releases up to 4.0; later versions are not known to be affected.
Risk and Exploitability
The CVSS score of 9.3 indicates a high severity. The vulnerability is exploitable over the network by any unauthenticated user; no credentials or elevated privileges are required. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Attackers can target storefront accounts via a simple HTTP PUT request, leading to full account takeover. The risk remains significant until a patch is applied, and vigilance is recommended.
OpenCVE Enrichment