Beveiligingsadvies

CVE-2023-36331

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-01-12 00:00:00
Laatst bijgewerkt 2026-01-12 20:12:16
Toegewezen door mitre
CVSS-score 8.2
Status PUBLISHED

Beschrijving

Incorrect access control in the /member/orderList API of xmall v1.1 allows attackers to arbitrarily access other users' order details via manipulation of the query parameter userId.