Impact
The vulnerability exists in the /order/paySuccess endpoint of Macrozheng Mall versions up to 1.0.3. An attacker can manipulate the orderId parameter to trigger the payment success workflow, effectively marking an order as paid without completing the actual transaction. This flaw is a business‑logic or authorization bypass that could enable fraudulent payments and financial losses.
Affected Systems
Affected product: Macrozheng Mall, versions up to 1.0.3. The vendor is macrozheng. The impact applies to deployments using the open‑source code repository at https://github.com/macrozheng/mall and the version range listed in the description.
Risk and Exploitability
The CVSS score of 5.3 indicates medium severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited documented exploitation. The flaw can be leveraged remotely by sending crafted HTTP requests to the /order/paySuccess endpoint with a modified orderId, assuming the endpoint is accessible and the attacker can determine valid order identifiers. Because the vendor has removed the GitHub issue without explanation, the attack surface may remain unpatched in current deployments.
OpenCVE Enrichment