Description
mall4j through 4.0 contains an improper authorization vulnerability that allows authenticated storefront customers to delete other shoppers' cart items through an operator precedence error in the cleanExpiryProdList SQL statement. Attackers can send one DELETE request to /p/shopCart/cleanExpiryProdList to remove every user's cart entries for off-shelf products, which do not return when products are restocked.
Published: 2026-10-11
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized Cart Item Deletion
Action: Apply Patch
AI Analysis

Impact

An operator precedence error in the cleanExpiryProdList SQL statement enables authenticated storefront customers to delete cart items belonging to other shoppers. The flaw allows an attacker to send a single DELETE request to the /p/shopCart/cleanExpiryProdList endpoint, after which every user's cart entries for off‑shelf products are removed. This leads to loss of cart data for all users and can disrupt the shopping experience, but does not provide code execution or privilege escalation.

Affected Systems

The vulnerability exists in the gz‑yami mall4j e‑commerce platform. All releases up to and including version 4.0 are affected. Users running any of these releases are potentially exposed.

Risk and Exploitability

The vulnerability has a CVSS score of 5.3, indicating a medium severity. The EPSS score is currently unavailable, and the issue is not listed in the CISA KEV catalog. Attackers require valid storefront credentials to access the endpoint, which means the risk is confined to authenticated users. Once authenticated, an attacker can delete all other users' temporary cart items. Because the flaw is based on a query ordering bug, exploitation does not need special privileges or advanced knowledge beyond sending a DELETE request.

Generated by OpenCVE AI on October 11, 2026 at 03:06 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update mall4j to a version newer than 4.0 or to the latest patched release.
  • If a patch is not yet available, modify the /p/shopCart/cleanExpiryProdList handler to validate that the cart items belong to the authenticated session before executing the delete operation.
  • Implement monitoring or alerts for bulk DELETE requests on the endpoint to detect and investigate anomalous deletion activity.

Generated by OpenCVE AI on October 11, 2026 at 03:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 11 Oct 2026 03:30:00 +0000

Type Values Removed Values Added
First Time appeared Gz-yami
Gz-yami mall4j
Vendors & Products Gz-yami
Gz-yami mall4j

Sun, 11 Oct 2026 01:45:00 +0000

Type Values Removed Values Added
Description mall4j through 4.0 contains an improper authorization vulnerability that allows authenticated storefront customers to delete other shoppers' cart items through an operator precedence error in the cleanExpiryProdList SQL statement. Attackers can send one DELETE request to /p/shopCart/cleanExpiryProdList to remove every user's cart entries for off-shelf products, which do not return when products are restocked.
Title mall4j through 4.0 Operator Precedence Error Deletes Other Users' Cart Items via /p/shopCart/cleanExpiryProdList
Weaknesses CWE-783
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-11T01:12:25.592Z

Reserved: 2026-10-10T23:06:26.839Z

Link: CVE-2026-108691

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-11T02:16:37.210

Modified: 2026-10-11T02:16:37.210

Link: CVE-2026-108691

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-11T03:15:08Z

Weaknesses
  • CWE-783

    Operator Precedence Logic Error