Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 28 Sep 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | mall4j through 4.0 fails to enforce authorization checks on GET endpoints in UserAddrController that retrieve customer address data. Authenticated attackers can call /user/addr/page and /user/addr/info endpoints to harvest all customer addresses including names, phone numbers, and postal information. | |
| Title | mall4j through 4.0 Missing Authorization in Admin User Address Endpoints | |
| Weaknesses | CWE-862 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-28T23:34:29.905Z
Reserved: 2026-09-28T22:50:19.577Z
Link: CVE-2026-102365
No data.
Status : Received
Published: 2026-09-29T00:17:03.777
Modified: 2026-09-29T00:17:03.777
Link: CVE-2026-102365
No data.
OpenCVE Enrichment
Updated: 2026-09-29T01:00:12Z