CVE-2026-82423

A vulnerability has been found in macrozheng mall up to 1.0.3. The affected element is an unknown function of the file /order/paySuccess of the component Payment Status Endpoint. The manipulation of the argument orderId leads to enforcement of behavioral workflow. The attack is possible to be carried out remotely. The vendor deleted the GitHub issue for this vulnerability without any explanation.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-29 23:17

Updated : 2026-09-01 03:16


NVD link : CVE-2026-82423

Mitre link : CVE-2026-82423

CVE.ORG link : CVE-2026-82423


JSON object : View

Products Affected

No product.

CWE
CWE-840

Business Logic Errors

CWE-841

Improper Enforcement of Behavioral Workflow