Impact
An operator precedence error in the cleanExpiryProdList SQL statement enables authenticated storefront customers to delete cart items belonging to other shoppers. The flaw allows an attacker to send a single DELETE request to the /p/shopCart/cleanExpiryProdList endpoint, after which every user's cart entries for off‑shelf products are removed. This leads to loss of cart data for all users and can disrupt the shopping experience, but does not provide code execution or privilege escalation.
Affected Systems
The vulnerability exists in the gz‑yami mall4j e‑commerce platform. All releases up to and including version 4.0 are affected. Users running any of these releases are potentially exposed.
Risk and Exploitability
The vulnerability has a CVSS score of 5.3, indicating a medium severity. The EPSS score is currently unavailable, and the issue is not listed in the CISA KEV catalog. Attackers require valid storefront credentials to access the endpoint, which means the risk is confined to authenticated users. Once authenticated, an attacker can delete all other users' temporary cart items. Because the flaw is based on a query ordering bug, exploitation does not need special privileges or advanced knowledge beyond sending a DELETE request.
OpenCVE Enrichment