CVE-2026-102365

Summary

mall4j through 4.0 fails to enforce authorization checks on GET endpoints in UserAddrController that retrieve customer address data. Authenticated attackers can call /user/addr/page and /user/addr/info endpoints to harvest all customer addresses including names, phone numbers, and postal information.

Affected Software

VendorProductVersion RangeStatus
gz-yamimall4j0 <= 4.0affected

Weaknesses

  • CWE-862: Missing Authorization

References