GHSA-239c-84f4-cp5fMediumCVSS 5.3

mall4j through 4.0 fails to implement authentication controls on the DELETE /prodComm endpoint in...

Published
September 29, 2026
Last Modified
September 29, 2026

🔗 CVE IDs covered (1)

📋 Description

mall4j through 4.0 fails to implement authentication controls on the DELETE /prodComm endpoint in ProdCommController. Unauthenticated attackers can delete arbitrary product reviews by supplying the prodCommId parameter without authorization checks.

🔗 References (6)