Executive brief
A security vulnerability has been identified in the macrozheng mall e-commerce platform, which provides online shopping and management services. An attacker could manipulate order identifiers during the return application process to potentially access or modify data they should not have permission to see. This could lead to unauthorized access to customer order information or disruption of the return processing system.
Technical details
The vulnerability is classified as Improper Control of Resource Identifiers (CWE-99) within the Portal Endpoint component of the macrozheng mall system. Specifically, the '/returnApply/create' endpoint fails to properly validate or restrict the 'orderId' argument. A remote attacker with low-level privileges (authenticated user) can manipulate this parameter to interact with resources (orders) they do not own. This could result in unauthorized data retrieval or modification of order return requests. While an exploit is reportedly available publicly, the vendor has not provided an official fix and reportedly deleted the original issue report.
Affected products
- macrozheng mall up to 1.0.3
Timeline
- 2026-07-09: disclosed: Vulnerability disclosed via VulDB and NVD
- 2026-07-09: advisory