CVE-2026-105573
Received Received - Intake

Business Logic Error in NewBee-Mall Shopping Cart

Vulnerability report for CVE-2026-105573, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: VulDB

Description

A vulnerability was found in newbee-ltd newbee-mall up to 2.7.5. This impacts an unknown function of the file /jshERP-boot/accountHead/updateAccountHeadAndDetail of the component Shopping Cart Quantity Handler. Performing a manipulation of the argument goodsCount results in business logic errors. The attack can be initiated remotely. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 6 associated CPEs
Vendor Product Version / Range
newbee-ltd newbee-mall 2.7.0
newbee-ltd newbee-mall 2.7.1
newbee-ltd newbee-mall 2.7.2
newbee-ltd newbee-mall 2.7.3
newbee-ltd newbee-mall 2.7.4
newbee-ltd newbee-mall 2.7.5

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-840 Business Logic Errors

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the newbee-mall e-commerce platform up to version 2.7.5. It involves a flaw in the shopping cart quantity handler where an authenticated user can manipulate the goodsCount argument to cause business logic errors. The issue allows negative cart quantities to be stored, which can corrupt order totals and inventory data when orders are processed.

Detection Guidance

Check for negative cart quantities in order submissions or database entries. Monitor for unusual stock increases after orders. Review application logs for requests to /jshERP-boot/accountHead/updateAccountHeadAndDetail with negative goodsCount values.

Impact Analysis

An attacker with a valid member account can exploit this to reduce order totals by using negative quantities, inflate product stock counters, and corrupt inventory data. For example, an order with a positive line of 500 and a negative line of -415 could result in a total of 85 while increasing the targeted product's stock from 998 to 1003. This can lead to financial losses and operational disruptions.

Compliance Impact

This vulnerability could impact compliance with GDPR and HIPAA by enabling unauthorized data manipulation. Negative cart quantities could alter order totals and inflate stock counters, leading to inaccurate financial records. For GDPR, this may affect data integrity requirements under Article 5. For HIPAA, it could compromise accurate inventory tracking in healthcare-related e-commerce systems.

Mitigation Strategies

Validate cart quantities to ensure they are positive integers during cart addition and order submission. Add database constraints to enforce positive stock values. Restrict negative values in the /jshERP-boot/accountHead/updateAccountHeadAndDetail endpoint.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105573. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart