Impact
The flaw resides in the /returnApply/create endpoint of the Portal component in macrozheng mall. Manipulating the orderId parameter lets an attacker provide arbitrary resource identifiers that have not been verified, effectively allowing unauthorized modification or deletion of resources. This improper control of resource identifiers (CWE‑99) can compromise confidentiality, integrity, and availability of the affected data, and the attack can be carried out remotely without requiring privileged credentials.
Affected Systems
All deployments of macrozheng mall version 1.0.3 or earlier are impacted, since the issue exists in the /returnApply/create function. The vulnerability affects the Portal Endpoint component; any version heavier than 1.0.3 is assumed to have the fix, but users should inspect release notes to confirm.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, but the low EPSS score (<1 %) suggests a modest risk of widespread exploitation in the wild. According to the description, the flaw is exploitable from a remote location by sending a crafted request to /returnApply/create with a manipulated orderId. A public exploit is available, meaning an attacker could immediately. The vulnerability is not listed in the CISA KEV catalog, implying no ongoing campaigns have been reported so far.
OpenCVE Enrichment