CVE-2023-36331 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

Incorrect access control in the /member/orderList API of xmall v1.1 allows attackers to arbitrarily access other users' order details via manipulation of the qu…
High CVSS: 8.2

CVE-2023-36331

Incorrect access control in the /member/orderList API of xmall v1.1 allows attackers to arbitrarily access other users' order details via manipulation of the query parameter userId.
Vendor
Exrick
Product
Xmall
CWE
CWE-639
Yayın Tarihi
2026-01-12 20:15:52
Güncelleme
2026-01-22 21:09:43
Source Identifier
cve@mitre.org
KEV Date Added
-

Kategoriler

Referanslar