Description
A vulnerability has been found in macrozheng mall up to 1.0.3. The affected element is an unknown function of the file /order/paySuccess of the component Payment Status Endpoint. The manipulation of the argument orderId leads to enforcement of behavioral workflow. The attack is possible to be carried out remotely. The vendor deleted the GitHub issue for this vulnerability without any explanation.
Published: 2026-08-29
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Business Logic Manipulation
Action: Assess Impact
AI Analysis

Impact

The vulnerability exists in the /order/paySuccess endpoint of Macrozheng Mall versions up to 1.0.3. An attacker can manipulate the orderId parameter to trigger the payment success workflow, effectively marking an order as paid without completing the actual transaction. This flaw is a business‑logic or authorization bypass that could enable fraudulent payments and financial losses.

Affected Systems

Affected product: Macrozheng Mall, versions up to 1.0.3. The vendor is macrozheng. The impact applies to deployments using the open‑source code repository at https://github.com/macrozheng/mall and the version range listed in the description.

Risk and Exploitability

The CVSS score of 5.3 indicates medium severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited documented exploitation. The flaw can be leveraged remotely by sending crafted HTTP requests to the /order/paySuccess endpoint with a modified orderId, assuming the endpoint is accessible and the attacker can determine valid order identifiers. Because the vendor has removed the GitHub issue without explanation, the attack surface may remain unpatched in current deployments.

Generated by OpenCVE AI on August 29, 2026 at 23:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Ensure the /order/paySuccess endpoint requires authentication and that the authenticated user’s role permits modifying that order, rejecting requests with mismatched or unauthorized orderId values.
  • Apply any available patch or upgrade to a newer version of Macrozheng Mall that addresses the payment status enforcement flaw; if no patched release exists, coordinate with the vendor for a fix.
  • Implement monitoring of payment state changes and generate alerts for suspicious orderId alterations or unauthorized status transitions; review logs regularly for evidence of exploitation.
  • As a temporary containment measure, restrict access to the paySuccess endpoint to trusted internal networks or disable it until a proper fix is in place.

Generated by OpenCVE AI on August 29, 2026 at 23:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 01 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 29 Aug 2026 22:30:00 +0000

Type Values Removed Values Added
Description A vulnerability has been found in macrozheng mall up to 1.0.3. The affected element is an unknown function of the file /order/paySuccess of the component Payment Status Endpoint. The manipulation of the argument orderId leads to enforcement of behavioral workflow. The attack is possible to be carried out remotely. The vendor deleted the GitHub issue for this vulnerability without any explanation.
Title macrozheng mall Payment Status Endpoint paySuccess behavioral workflow
First Time appeared Macrozheng
Macrozheng mall
Weaknesses CWE-840
CWE-841
CPEs cpe:2.3:a:macrozheng:mall:*:*:*:*:*:*:*:*
Vendors & Products Macrozheng
Macrozheng mall
References
Metrics cvssV2_0

{'score': 5.5, 'vector': 'AV:N/AC:L/Au:S/C:N/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 5.4, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-01T02:17:29.639Z

Reserved: 2026-08-29T06:29:17.034Z

Link: CVE-2026-82423

cve-icon Vulnrichment

Updated: 2026-09-01T02:17:25.433Z

cve-icon NVD

Status : Deferred

Published: 2026-08-29T23:17:23.900

Modified: 2026-09-01T03:16:51.833

Link: CVE-2026-82423

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-29T23:30:17Z

Weaknesses