Sceawere
Vulnerability Detail
CVE-2026-102362UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Unauthenticated Review Deletion Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.3
- Creation Date
- 7h ago
- Vendor
- gz-yami
- Product
- mall4j
- Attack Type
- Missing Authentication for Critical Function
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
mall4j through 4.0 fails to implement authentication controls on the DELETE /prodComm endpoint in ProdCommController. Unauthenticated attackers can delete arbitrary product reviews by supplying the prodCommId parameter without authorization checks.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.3",
"pubDate": "2026-09-29T00:17:03.337Z",
"pubdate": "2026-09-29T00:17:03.337Z",
"executiveSummary": "The mall4j e-commerce platform through version 4.0 contains a critical Broken Access Control (BAC) vulnerability within the product comment management module. The flaw resides in the ProdCommController, specifically affecting the DELETE /prodComm endpoint. This security oversight allows any unauthenticated network actor to invoke the deletion function for product reviews without requiring valid session tokens or administrative privileges.\nThe vulnerability stems from the absence of server-side authorization checks on the request handler. Consequently, an attacker can delete arbitrary product reviews simply by supplying a valid prodCommId parameter through a standard HTTP DELETE request. The impact of this exploit includes the permanent removal of customer feedback, potential reputation damage, and the systematic sabotage of e-commerce storefront integrity. Since no authentication is required, the exploitation path is trivial, requiring only network reachability to the application. This poses a significant risk to the availability and integrity of user-generated content within the mall4j ecosystem.",
"technicalDetails": "The vulnerability is classified as an Improper Authorization flaw, specifically categorized under Broken Access Control. In the mall4j framework version 4.0, the ProdCommController class manages operations related to product comments. Analysis of the source code indicates that the DELETE /prodComm endpoint lacks integration with the application's security interceptors or role-based access control (RBAC) mechanisms.\nThe root cause is the failure to implement mandatory authorization checks within the controller method responsible for handling deletions. In a secure implementation, the application should verify the identity of the requester and ensure they possess the necessary permissions (e.g., administrator or owner of the comment) before proceeding with the database operation. Because this validation logic is omitted, the application processes the request based solely on the provided URI parameters.\nThe exploitation flow is straightforward and does not require complex reconnaissance or authentication bypass techniques. An attacker identifies the target endpoint (DELETE /prodComm) and observes that it expects a prodCommId parameter. By crafting a raw HTTP request—for example, 'DELETE /prodComm?prodCommId=123'—the attacker can trigger the underlying backend service to execute the deletion logic associated with that ID. Since the controller does not perform a session validation check, the database management layer receives a command to drop the record from the product comment table regardless of the origin of the request.\nThis vulnerability is reachable via any network interface that has access to the web server, making it a remote exploitable issue. The lack of privilege requirements significantly lowers the barrier to entry, enabling automated scripts to iterate through ranges of prodCommId values to perform mass deletion of reviews. Post-exploitation, the impact is strictly limited to unauthorized data modification and deletion; however, the business impact of losing historical user feedback, review ratings, and social proof is substantial for e-commerce platforms. The system fails to provide any audit logging or interception to prevent unprivileged entities from mutating the state of the product comment repository, indicating a systemic failure in the controller's middleware security configuration."
}