Description
mall4j through 4.0 contains an information disclosure vulnerability that allows authenticated customers to read other shoppers' cart items due to an operator precedence error in the getShopCartExpiryItems SQL filter. Attackers with any storefront account can request GET /p/shopCart/expiryProdList to retrieve off-shelf product basket entries including product, SKU, quantity, shop, and promoter card numbers.
Published: 2026-10-11
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Information Disclosure
Action: Immediate Patch
AI Analysis

Impact

An operator precedence flaw in Mall4j's getShopCartExpiryItems SQL filter allows an authenticated customer to query the /p/shopCart/expiryProdList endpoint and retrieve off‑shelf basket entries that belong to other users. The data returned includes product identifiers, SKU, quantity, shop name, and promoter card numbers, exposing private shopping information. This weakness is classified as CWE-783, an improper access control issue, and the official CVSS score of 5.3 indicates moderate severity.

Affected Systems

Mall4j version 4.0 and earlier, distributed by gz-yami, are affected. Any deployment of these releases that exposes the /p/shopCart/expiryProdList endpoint to authenticated storefront users is vulnerable.

Risk and Exploitability

Because the vulnerability requires only authentication and an HTTP GET request to a known endpoint, attackers with a storefront account can exploit it remotely. The EPSS score is not available, and the vulnerability does not appear in CISA's KEV catalog, so the current public exploitation risk is moderate. However, the privacy impact of leaking other customers’ cart contents means an injured party may be able to infer shopping habits or discount usage. The CVSS base score of 5.3 confirms the medium impact on confidentiality, and there are no known active exploits at this time.

Generated by OpenCVE AI on October 11, 2026 at 03:07 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Mall4j to a version that has the getShopCartExpiryItems filter corrected or apply the vendor’s hotfix.
  • Add a check in the /p/shopCart/expiryProdList handler that compares the caller’s user ID with the owner of the cart before executing the query.
  • Disable or lock down the /p/shopCart/expiryProdList endpoint until the patch or control logic is in place.

Generated by OpenCVE AI on October 11, 2026 at 03:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 11 Oct 2026 03:30:00 +0000

Type Values Removed Values Added
First Time appeared Gz-yami
Gz-yami mall4j
Vendors & Products Gz-yami
Gz-yami mall4j

Sun, 11 Oct 2026 01:45:00 +0000

Type Values Removed Values Added
Description mall4j through 4.0 contains an information disclosure vulnerability that allows authenticated customers to read other shoppers' cart items due to an operator precedence error in the getShopCartExpiryItems SQL filter. Attackers with any storefront account can request GET /p/shopCart/expiryProdList to retrieve off-shelf product basket entries including product, SKU, quantity, shop, and promoter card numbers.
Title mall4j through 4.0 Operator Precedence Error Exposes Other Users' Cart Items via /p/shopCart/expiryProdList
Weaknesses CWE-783
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-11T01:12:24.928Z

Reserved: 2026-10-10T23:06:26.531Z

Link: CVE-2026-108690

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-11T02:16:37.057

Modified: 2026-10-11T02:16:37.057

Link: CVE-2026-108690

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-11T03:15:08Z

Weaknesses
  • CWE-783

    Operator Precedence Logic Error