Impact
mall4j versions up to 4.0 lack authorization checks on GET endpoints in UserAddrController that retrieve customer address data. This flaw (CWE‑862) allows any authenticated user to call /user/addr/page and /user/addr/info and harvest all customers’ names, phone numbers, and postal information, resulting in unauthorized disclosure of personally identifiable information for every user in the system.
Affected Systems
The vulnerability affects the mall4j web store application provided by the gz‑yami vendor. All releases up to and including version 4.0 are vulnerable; no later versions are mentioned in the CVE data.
Risk and Exploitability
With a CVSS score of 7.1 the flaw is classified as high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, indicating no known exploitation in the wild at present. The attack requires only a valid authenticated session and does not need elevated privileges; once an attacker can log in, the missing authorization checks make the exploitation trivial, enabling complete harvesting of customer address data.
OpenCVE Enrichment