Description
A security vulnerability has been detected in macrozheng mall up to 1.0.3. Affected is the function OmsCartItemServiceImpl.updateQuantity of the file /cart/update/quantity. The manipulation of the argument quantity leads to business logic errors. The attack may be initiated remotely. The vendor deleted the GitHub issue for this vulnerability without any explanation.
Published: 2026-08-25
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Business Logic Disruption
Action: Apply Patch
AI Analysis

Impact

The flaw is in the OmsCartItemServiceImpl.updateQuantity endpoint of macrozheng mall. Supplying an altered quantity value causes a logic error that lets the requester change the cart quantity without proper validation. The result is a business‑logic failure that can affect inventory or billing accuracy.

Affected Systems

All installations of macrozheng mall releases up to and including 1.0.3 are vulnerable. The flaw is in the /cart/update/quantity endpoint and applies to every deployment that has not upgraded beyond version 1.0.3.

Risk and Exploitability

The CVSS score is 5.3, indicating moderate severity. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, so no widespread exploitation is known. Because the endpoint can be invoked remotely through HTTP, the attacker only needs network access to the service; the required payload is the modified quantity parameter. The remote nature of the trigger is stated in the description, and the ease of sending an HTTP request is inferred from typical web service behavior.

Generated by OpenCVE AI on August 25, 2026 at 15:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade macrozheng mall to a version newer than 1.0.3 when a vendor patch becomes available.
  • If an immediate patch is not available, enforce server‑side validation that bounds quantity changes to acceptable business rules, and consider restricting the /cart/update/quantity endpoint to authenticated users.
  • Deploy monitoring or logging to detect abnormal quantity requests and alert on potential misuse.

Generated by OpenCVE AI on August 25, 2026 at 15:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 27 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 25 Aug 2026 13:15:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been detected in macrozheng mall up to 1.0.3. Affected is the function OmsCartItemServiceImpl.updateQuantity of the file /cart/update/quantity. The manipulation of the argument quantity leads to business logic errors. The attack may be initiated remotely. The vendor deleted the GitHub issue for this vulnerability without any explanation.
Title macrozheng mall quantity OmsCartItemServiceImpl.updateQuantity logic error
First Time appeared Macrozheng
Macrozheng mall
Weaknesses CWE-840
CPEs cpe:2.3:a:macrozheng:mall:*:*:*:*:*:*:*:*
Vendors & Products Macrozheng
Macrozheng mall
References
Metrics cvssV2_0

{'score': 4, 'vector': 'AV:N/AC:L/Au:S/C:N/I:P/A:N/E:ND/RL:ND/RC:UR'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N/E:X/RL:X/RC:R'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N/E:X/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-27T15:14:14.547Z

Reserved: 2026-08-25T06:29:08.986Z

Link: CVE-2026-79406

cve-icon Vulnrichment

Updated: 2026-08-27T15:14:10.291Z

cve-icon NVD

Status : Deferred

Published: 2026-08-25T13:19:32.433

Modified: 2026-08-27T17:20:47.557

Link: CVE-2026-79406

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T15:15:04Z

Weaknesses