CVE-2026-82423
Received Received - Intake

Remote Code Execution in MacroZheng Mall Payment Endpoint

Vulnerability report for CVE-2026-82423, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-29

Last updated on: 2026-08-29

Assigner: VulDB

Description

A vulnerability has been found in macrozheng mall up to 1.0.3. The affected element is an unknown function of the file /order/paySuccess of the component Payment Status Endpoint. The manipulation of the argument orderId leads to enforcement of behavioral workflow. The attack is possible to be carried out remotely. The vendor deleted the GitHub issue for this vulnerability without any explanation.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-29
Last Modified
2026-08-29
Generated
2026-08-30
AI Q&A
2026-08-30
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
macrozheng mall to 1.0.3 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-840 Business Logic Errors
CWE-841 The product supports a session in which more than one behavior must be performed by an actor, but it does not properly ensure that the actor performs the behaviors in the required sequence.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the macrozheng mall software up to version 1.0.3. It is located in the Payment Status Endpoint at the file /order/paySuccess. The issue involves manipulation of the orderId parameter, which can enforce unintended behavioral workflows. The attack can be executed remotely without requiring special privileges.

Detection Guidance

This vulnerability involves the /order/paySuccess endpoint in macrozheng mall up to 1.0.3, where the orderId parameter may be manipulated to alter workflow behavior. To detect it, monitor HTTP POST requests to /order/paySuccess for unusual orderId values or unexpected state changes. Check application logs for anomalies in payment processing workflows.

Impact Analysis

The vulnerability may allow attackers to alter payment workflows by manipulating the orderId parameter. This could lead to unauthorized order processing or status changes. The impact is limited as it requires user interaction and has a low attack complexity, but it may disrupt normal operations.

Compliance Impact

The provided CVE data does not specify any direct impact on compliance with GDPR, HIPAA, or other standards. The vulnerability involves enforcement of behavioral workflow manipulation via the orderId parameter in the Payment Status Endpoint, but no compliance-related consequences are mentioned.

Mitigation Strategies

Immediately upgrade macrozheng mall to a version beyond 1.0.3 where the vulnerability is patched. If no patch is available, consider disabling the /order/paySuccess endpoint or restricting access to trusted users only. Monitor network traffic for unusual activity related to orderId manipulation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-82423. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart