CVE-2026-102365

CVE-2026-102365 published: mall4j through 4.0 fails to enforce authorization checks on GET endpoints in UserAddrController that retrieve customer address data. Authenticated attackers can call /user/addr/page and /user/addr/info endpoints to harvest all customer addresses including n...

View full NVD advisory → ← Back to CVE watch