HIGH
Incorrect access control in the /member/orderList API of xmall v1.1 allows attackers to arbitrarily access other users' order details via manipulation of the query parameter userId
Published Jan 12, 2026
8.2
HIGHCVSS 3.1
EPSS 0.23%
Description
Affected products
Remediation
Metrics
References (1)
Change history (0)
No recorded changes yet.