top of page
perceptive_background_267k.jpg

Incorrect access control in the /member/orderList API of xmall v1.1 allows attackers to arbitrarily access other users' order details via manipulation of the qu…

Published:

11 January 2026 at 23:00:00

Alert date:

12 January 2026 at 22:01:09

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Identity & Access

CVE-2023-36331 affects xmall v1.1, an e-commerce application. The vulnerability exists in the /member/orderList API endpoint due to incorrect access control implementation. Attackers can manipulate the userId query parameter to access other users' order details without proper authorization. This represents a classic Insecure Direct Object Reference (IDOR) vulnerability that allows horizontal privilege escalation. The flaw enables unauthorized access to sensitive customer order information, potentially exposing personal and financial data. The vulnerability has been reported on GitHub and assigned a high criticality rating.

Technical details

Mitigation steps:

Affected products:

xmall

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page