Impact
Mall4j versions up to 4.0 do not validate the sysType field within sa-token sessions, which allows a storefront customer to reuse their session token as a back‑office user. The flaw permits attackers to register a normal storefront account and then use that session token to authenticate against the admin API, bypassing authorization checks. As a result, attackers can retrieve confidential system menus, upload arbitrary files, and modify configuration endpoints that are intended for administrators only.
Affected Systems
The vulnerability affects the gz‑yami Mall4j e‑commerce platform, specifically all releases through version 4.0. No other vendors or products are listed as affected by this issue.
Risk and Exploitability
The CVSS score of 5.3 indicates a medium level of severity, while the EPSS score is not available. The flaw is not listed in the CISA KEV catalog. Attackers need only access the public storefront to register an account; no special privileges or network access beyond the ordinary electorate are required. The exploit path is straightforward: acquire a valid storefront token, then send requests to admin URLs that lack further permission checks. Because the flaw requires no code execution, the risk is primarily confined to misappropriation of administrative functions and potential data exposure.
OpenCVE Enrichment