A security vulnerability has been detected in macrozheng mall up to 1.0.3. Affected is the function OmsCartItemServiceImpl.updateQuantity of the file /cart/update/quantity. The manipulation of the argument quantity leads to business logic errors. The attack may be initiated remotely. The vendor deleted the GitHub issue for this vulnerability without any explanation.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/79xxx/CVE-2026-79406.json",
"cwe_ids": [
"CWE-840"
],
"cna_assigner": "VulDB"
}{
"extracted_events": [
{
"introduced": "1.0.0"
},
{
"last_affected": "1.0.0"
},
{
"introduced": "1.0.1"
},
{
"last_affected": "1.0.1"
},
{
"introduced": "1.0.2"
},
{
"last_affected": "1.0.2"
},
{
"introduced": "1.0.3"
},
{
"last_affected": "1.0.3"
}
],
"source": "AFFECTED_FIELD"
}