CVE-2026-79406

Source
https://cve.org/CVERecord?id=CVE-2026-79406
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-79406.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-79406
Published
2026-08-25T13:00:09.821Z
Modified
2026-08-28T03:30:24.866877896Z
Severity
  • 5.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X CVSS Calculator
Summary
macrozheng mall quantity OmsCartItemServiceImpl.updateQuantity logic error
Details

A security vulnerability has been detected in macrozheng mall up to 1.0.3. Affected is the function OmsCartItemServiceImpl.updateQuantity of the file /cart/update/quantity. The manipulation of the argument quantity leads to business logic errors. The attack may be initiated remotely. The vendor deleted the GitHub issue for this vulnerability without any explanation.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/79xxx/CVE-2026-79406.json",
    "cwe_ids": [
        "CWE-840"
    ],
    "cna_assigner": "VulDB"
}
References

Affected packages

Git / github.com/macrozheng/mall

Affected ranges

Type
GIT
Repo
https://github.com/macrozheng/mall
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "1.0.0"
        },
        {
            "last_affected": "1.0.0"
        },
        {
            "introduced": "1.0.1"
        },
        {
            "last_affected": "1.0.1"
        },
        {
            "introduced": "1.0.2"
        },
        {
            "last_affected": "1.0.2"
        },
        {
            "introduced": "1.0.3"
        },
        {
            "last_affected": "1.0.3"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

1.*
1.0.0
1.0.1
1.0.2
1.0.3
v1.*
v1.0.0
v1.0.1
v1.0.2
v1.0.3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-79406.json"