Sceawere
Vulnerability Detail
CVE-2026-19361UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
macroheng mall Weak Password Recovery
Vulnerability Metadata
- Severity
- Low
- Score / CVSS
- 3.7
- Creation Date
- 4h ago
- Vendor
- macrozheng
- Product
- mall
- Attack Type
- Weak Password Recovery
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
- Attack Complexity
- HIGH
Narrative and Response
Description
A flaw has been found in macrozheng mall 0504e86. This vulnerability affects unknown code of the file /sso/getAuthCode of the component mall-portal Module. Executing a manipulation can lead to weak password recovery. The attack may be launched remotely. This attack is characterized by high complexity. It is stated that the exploitability is difficult. The exploit has been published and may be used. The vendor deleted the GitHub issue for this vulnerability without any explanation. Afterwards the vendor was contacted early about this disclosure via email but did not respond in any way.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "3.7",
"pubDate": "2026-08-09T18:16:42.930Z",
"pubdate": "2026-08-09T18:16:42.930Z",
"executiveSummary": "A vulnerability has been identified in macrozheng mall 0504e86, specifically within the mall-portal module handling requests to the /sso/getAuthCode endpoint. This security flaw enables weak password recovery mechanics that can be exploited by remote threat actors. The vulnerability is characterized by a high degree of complexity and difficult exploitability requirements. Despite these barriers, a public exploit has been made available. The vendor exhibited unresponsiveness during early disclosure attempts and deleted the corresponding GitHub issue without providing an explanation. If successfully exploited, the vulnerability compromises authentication integrity by facilitating unauthorized password recovery processes. Organizations utilizing the affected software face potential account takeover risks, necessitating heightened monitoring and defensive hardening despite the high complexity of the attack vector.",
"technicalDetails": "The vulnerability resides in the mall-portal component of macrozheng mall version 0504e86, specifically targeting the /sso/getAuthCode file and associated functionality. The root cause stems from insecure design or implementation within the password recovery workflow, which generates or validates authentication codes in a manner vulnerable to manipulation. Because the endpoint is exposed over the network, attackers can interact with the service remotely without prior authentication or elevated privileges.\nThe attack flow begins with the remote adversary targeting the /sso/getAuthCode endpoint within the mall-portal module. Due to the high complexity and difficult exploitability associated with this flaw, successful exploitation likely requires precise manipulation of request parameters, sequence prediction, or state bypasses during the password recovery phase. When the vulnerable function processes the crafted payload, it fails to enforce robust cryptographic randomness, rate limiting, or proper validation checks, thereby allowing the attacker to subvert the intended security controls governing password recovery.\nPost-exploitation impact includes the potential unauthorized generation of valid authorization codes, which subsequently permits the adversary to initiate and complete password resets for targeted user accounts. This leads directly to account compromise and unauthorized access to sensitive user data within the mall-portal environment. Network exposure is confirmed via the HTTP/HTTPS accessibility of the /sso/getAuthCode endpoint. Given the lack of vendor response, official patched versions are currently unavailable, increasing the residual risk for deployed instances."
}