CVE-2026-108690
Received
Received - Intake
Information Disclosure in mall4j Shopping Cart
Vulnerability report for CVE-2026-108690, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-10-11
Last updated on: 2026-10-11
Assigner: VulnCheck
Description
Description
mall4j through 4.0 contains an information disclosure vulnerability that allows authenticated customers to read other shoppers' cart items due to an operator precedence error in the getShopCartExpiryItems SQL filter. Attackers with any storefront account can request GET /p/shopCart/expiryProdList to retrieve off-shelf product basket entries including product, SKU, quantity, shop, and promoter card numbers.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| gz-yami | mall4j | 0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-783 | The product uses an expression in which operator precedence causes incorrect logic to be used. |