Security Advisory

CVE-2023-36331

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-01-12 00:00:00
Last updated 2026-01-12 20:12:16
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Incorrect access control in the /member/orderList API of xmall v1.1 allows attackers to arbitrarily access other users' order details via manipulation of the query parameter userId.