Impact
An operator precedence flaw in Mall4j's getShopCartExpiryItems SQL filter allows an authenticated customer to query the /p/shopCart/expiryProdList endpoint and retrieve off‑shelf basket entries that belong to other users. The data returned includes product identifiers, SKU, quantity, shop name, and promoter card numbers, exposing private shopping information. This weakness is classified as CWE-783, an improper access control issue, and the official CVSS score of 5.3 indicates moderate severity.
Affected Systems
Mall4j version 4.0 and earlier, distributed by gz-yami, are affected. Any deployment of these releases that exposes the /p/shopCart/expiryProdList endpoint to authenticated storefront users is vulnerable.
Risk and Exploitability
Because the vulnerability requires only authentication and an HTTP GET request to a known endpoint, attackers with a storefront account can exploit it remotely. The EPSS score is not available, and the vulnerability does not appear in CISA's KEV catalog, so the current public exploitation risk is moderate. However, the privacy impact of leaking other customers’ cart contents means an injured party may be able to infer shopping habits or discount usage. The CVSS base score of 5.3 confirms the medium impact on confidentiality, and there are no known active exploits at this time.
OpenCVE Enrichment