CVE-2026-79406
Received Received - Intake

BaseFortify

Vulnerability report for CVE-2026-79406, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-25

Last updated on: 2026-08-25

Assigner: VulDB

Description

A security vulnerability has been detected in macrozheng mall up to 1.0.3. Affected is the function OmsCartItemServiceImpl.updateQuantity of the file /cart/update/quantity. The manipulation of the argument quantity leads to business logic errors. The attack may be initiated remotely. The vendor deleted the GitHub issue for this vulnerability without any explanation.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-25
Last Modified
2026-08-25
Generated
2026-08-25
AI Q&A
2026-08-25
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
macrozheng mall to 1.0.3 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-840 Business Logic Errors

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects macrozheng mall up to version 1.0.3. It is located in the function OmsCartItemServiceImpl.updateQuantity within the file /cart/update/quantity. The issue arises when the quantity argument is manipulated, leading to business logic errors. The attack can be executed remotely.

Detection Guidance

This vulnerability affects the macrozheng mall system up to version 1.0.3, specifically the function OmsCartItemServiceImpl.updateQuantity. To detect it, check if your system is running an affected version of macrozheng mall. Inspect the cart/update/quantity endpoint for improper input validation on the quantity parameter. Monitor logs for unusual business logic errors or unauthorized quantity modifications.

Impact Analysis

The vulnerability may allow attackers to manipulate cart quantities remotely, causing incorrect business logic operations. This could lead to financial discrepancies, incorrect inventory tracking, or other unintended system behaviors affecting users or the business.

Compliance Impact

The vulnerability allows manipulation of the quantity argument in the cart update function, which could lead to business logic errors. This may impact data integrity and audit trails, potentially affecting compliance with standards requiring accurate transaction records such as GDPR (data accuracy) and HIPAA (audit controls). However, specific compliance impacts are not detailed in the provided text.

Mitigation Strategies

Upgrade macrozheng mall to a version beyond 1.0.3 to address the vulnerability in OmsCartItemServiceImpl.updateQuantity. Review and validate business logic related to cart quantity updates to prevent manipulation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-79406. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart