Description
mall4j through 4.0 fails to enforce authorization checks on GET endpoints in UserAddrController that retrieve customer address data. Authenticated attackers can call /user/addr/page and /user/addr/info endpoints to harvest all customer addresses including names, phone numbers, and postal information.
Published: 2026-09-28
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: Unauthorized disclosure of customer address data
Action: Immediate Patch
AI Analysis

Impact

mall4j versions up to 4.0 lack authorization checks on GET endpoints in UserAddrController that retrieve customer address data. This flaw (CWE‑862) allows any authenticated user to call /user/addr/page and /user/addr/info and harvest all customers’ names, phone numbers, and postal information, resulting in unauthorized disclosure of personally identifiable information for every user in the system.

Affected Systems

The vulnerability affects the mall4j web store application provided by the gz‑yami vendor. All releases up to and including version 4.0 are vulnerable; no later versions are mentioned in the CVE data.

Risk and Exploitability

With a CVSS score of 7.1 the flaw is classified as high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, indicating no known exploitation in the wild at present. The attack requires only a valid authenticated session and does not need elevated privileges; once an attacker can log in, the missing authorization checks make the exploitation trivial, enabling complete harvesting of customer address data.

Generated by OpenCVE AI on September 29, 2026 at 00:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑published patch or upgrade to a version newer than 4.0 that enforces proper authorization checks for the /user/addr/* endpoints.
  • If an upgrade is not immediately possible, implement role‑based access control on all GET operations in UserAddrController so that only privileged staff can retrieve address data.
  • Configure network or application firewalls to monitor or block suspicious access to the /user/addr/* endpoints and review logs for unauthorized activity.

Generated by OpenCVE AI on September 29, 2026 at 00:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description mall4j through 4.0 fails to enforce authorization checks on GET endpoints in UserAddrController that retrieve customer address data. Authenticated attackers can call /user/addr/page and /user/addr/info endpoints to harvest all customer addresses including names, phone numbers, and postal information.
Title mall4j through 4.0 Missing Authorization in Admin User Address Endpoints
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-28T23:34:29.905Z

Reserved: 2026-09-28T22:50:19.577Z

Link: CVE-2026-102365

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-29T00:17:03.777

Modified: 2026-09-29T00:17:03.777

Link: CVE-2026-102365

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-29T01:00:12Z

Weaknesses