Impact
The vulnerability in mall4j 4.0 allows a disabled user account to maintain an active session by repeatedly calling the POST /token/refresh endpoint. The token refresh logic ignores the enabled flag, so the system issues a new session token even when the account is marked as inactive. This bypasses the intended access revocation mechanism, letting a user persist privileges after disabling, effectively turning the account into a long‑lived, unauthorized session – a classic example of improper restriction of operations (CWE‑613).
Affected Systems
Affected systems are all installations of the mall4j framework version 4.0 and below, provided by the vendor gz‑yami. The issue is present across all modules that expose the token refresh API, as seen in the source paths in the referenced repository. Clients that have not applied a newer release or have not patched the token store code are vulnerable.
Risk and Exploitability
The CVSS score of 5.3 indicates medium severity. The exploit requires an existing session token for the disabled account, which can be obtained if an attacker has previously authenticated. There is no documented public exploit, and the EPSS value is not available, but the missing validation permits an attacker who can acquire a token to continuously refresh it. The vulnerability is not listed in CISA's KEV catalog, suggesting limited real‑world exploitation to date, though the impact on compromised accounts is significant.
OpenCVE Enrichment