Description
A vulnerability has been found in macrozheng mall up to 1.0.3. The affected element is an unknown function of the file /order/paySuccess of the component Payment Status Endpoint. The manipulation of the argument orderId leads to enforcement of behavioral workflow. The attack is possible to be carried out remotely. The vendor deleted the GitHub issue for this vulnerability without any explanation.
Published: 2026-08-29
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability exists in the /order/paySuccess endpoint of Macrozheng Mall versions up to 1.0.3. An attacker can manipulate the orderId parameter to trigger the payment success workflow, effectively marking an order as paid without completing the actual transaction. This flaw is a business‑logic or authorization bypass that could enable fraudulent payments and financial losses.

Affected Systems

Affected product: Macrozheng Mall, versions up to 1.0.3. The vendor is macrozheng. The impact applies to deployments using the open‑source code repository at https://github.com/macrozheng/mall and the version range listed in the description.

Risk and Exploitability

The CVSS score of 5.3 indicates medium severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited documented exploitation. The flaw can be leveraged remotely by sending crafted HTTP requests to the /order/paySuccess endpoint with a modified orderId, assuming the endpoint is accessible and the attacker can determine valid order identifiers. Because the vendor has removed the GitHub issue without explanation, the attack surface may remain unpatched in current deployments.

Generated by OpenCVE AI on August 29, 2026 at 23:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Ensure the /order/paySuccess endpoint requires authentication and that the authenticated user’s role permits modifying that order, rejecting requests with mismatched or unauthorized orderId values.
  • Apply any available patch or upgrade to a newer version of Macrozheng Mall that addresses the payment status enforcement flaw; if no patched release exists, coordinate with the vendor for a fix.
  • Implement monitoring of payment state changes and generate alerts for suspicious orderId alterations or unauthorized status transitions; review logs regularly for evidence of exploitation.
  • As a temporary containment measure, restrict access to the paySuccess endpoint to trusted internal networks or disable it until a proper fix is in place.

Generated by OpenCVE AI on August 29, 2026 at 23:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 29 Aug 2026 22:30:00 +0000

Type Values Removed Values Added
Description A vulnerability has been found in macrozheng mall up to 1.0.3. The affected element is an unknown function of the file /order/paySuccess of the component Payment Status Endpoint. The manipulation of the argument orderId leads to enforcement of behavioral workflow. The attack is possible to be carried out remotely. The vendor deleted the GitHub issue for this vulnerability without any explanation.
Title macrozheng mall Payment Status Endpoint paySuccess behavioral workflow
First Time appeared Macrozheng
Macrozheng mall
Weaknesses CWE-840
CWE-841
CPEs cpe:2.3:a:macrozheng:mall:*:*:*:*:*:*:*:*
Vendors & Products Macrozheng
Macrozheng mall
References
Metrics cvssV2_0

{'score': 5.5, 'vector': 'AV:N/AC:L/Au:S/C:N/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 5.4, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-29T22:15:10.867Z

Reserved: 2026-08-29T06:29:17.034Z

Link: CVE-2026-82423

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-29T23:17:23.900

Modified: 2026-08-29T23:17:23.900

Link: CVE-2026-82423

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-29T23:30:17Z

Weaknesses