GHSA-q842-qqjh-38pvHighCVSS 6.5

mall4j through 4.0 fails to enforce authorization checks on GET endpoints in UserAddrController...

Published
September 29, 2026
Last Modified
September 29, 2026

🔗 CVE IDs covered (1)

📋 Description

mall4j through 4.0 fails to enforce authorization checks on GET endpoints in UserAddrController that retrieve customer address data. Authenticated attackers can call /user/addr/page and /user/addr/info endpoints to harvest all customer addresses including names, phone numbers, and postal information.

🔗 References (6)