Impact
Mall4j through version 4.0 is missing authentication in the DeliveryController checkDelivery endpoint, allowing attackers to supply an order number and obtain full shipment tracking details. The disclosed information includes carrier names, waybill numbers and the complete logistics trail for any order. This represents a confidentiality breach as no identity or ownership verification is performed before data is returned, exposing sensitive logistical information to unauthenticated users.
Affected Systems
The vulnerability affects the Mall4j application developed by gz‑yami, impacting all releases up to and including version 4.0. Any deployment of these versions that exposes the DeliveryController checkDelivery endpoint to external clients is susceptible.
Risk and Exploitability
The CVSS score of 6.3 classifies the issue as moderate. EPSS information is not available, indicating that the current data does not provide a clear estimate of exploitation likelihood, but the vulnerability can be exploited remotely over the web interface without any credentials. The vulnerability is not listed in CISA’s KEV catalog. Attackers can obtain shipping details for any order simply by sending a request with an order number, making it trivial for malicious actors to gather potentially sensitive logistics data.
OpenCVE Enrichment