Executive brief
ShopXO, an e-commerce platform, contains a security flaw in its scheduled task management system. An unauthorized attacker can remotely trigger internal maintenance tasks that should be restricted. This can lead to business-logic tampering, such as forcing order confirmations, closing orders prematurely, or manipulating customer reward points, potentially causing financial loss and operational disruption.
Technical details
An authorization bypass vulnerability exists in ShopXO up to version 6.7.1 within the 'Scheduled Task Endpoint' component. The flaw is located in the file 'app/api/controller/Crontab.php' and affects functions including OrderClose, OrderSuccess, PayLogOrderClose, and GoodsGiveIntegral. Because these endpoints lack proper authentication checks, a remote attacker can trigger them via direct HTTP requests. This allows for the unauthorized execution of crontab-related business logic, such as forcing order completions or manipulating integral rewards. A public exploit has been disclosed, and as of the advisory date, the vendor has not provided a patch.
Affected products
- Gong Fuxiang (ShopXO) ShopXO up to 6.7.1
Timeline
- 2026-06-15: advisory: NVD publication date
- 2026-06-15: disclosed: Public disclosure of the exploit on GitHub