Impact
A race condition exists in the Order Submission functionality of macrozheng mall up to version 1.0.3. The flaw can be triggered via the /order/submit endpoint and is remotely reachable. The attacker must coordinate simultaneous requests, which is considered to have high complexity, and the vulnerability is described as difficult to exploit. The consequence is a breakdown in consistent order handling, potentially leading to duplicated or lost orders or a denial of service on the checkout flow.
Affected Systems
The affected product is macrozheng mall, versions up to and including 1.0.3. No specific patch version is listed in the advisory; users should verify whether later releases contain a fix.
Risk and Exploitability
The CVSS score of 2.3 indicates a low overall severity. No EPSS score is available, and the vulnerability is not catalogued in CISA’s KEV list. Because the attack requires concurrent requests and the vulnerability is described as difficult to exploit, the expected likelihood of real-world exploitation is low. The primary risk would be for services exposed to the public internet, where malicious actors could attempt to trigger the race condition. Even if exploited, the impact is confined to the ordering subsystem rather than the entire system.
OpenCVE Enrichment