

Incorrect access control in the /member/orderList API of xmall v1.1 allows attackers to arbitrarily access other users' order details via manipulation of the qu…
Published:
11 January 2026 at 23:00:00
Alert date:
12 January 2026 at 22:01:09
Source:
nvd.nist.gov
Web Technologies, Identity & Access
CVE-2023-36331 affects xmall v1.1, an e-commerce application. The vulnerability exists in the /member/orderList API endpoint due to incorrect access control implementation. Attackers can manipulate the userId query parameter to access other users' order details without proper authorization. This represents a classic Insecure Direct Object Reference (IDOR) vulnerability that allows horizontal privilege escalation. The flaw enables unauthorized access to sensitive customer order information, potentially exposing personal and financial data. The vulnerability has been reported on GitHub and assigned a high criticality rating.
Technical details
Mitigation steps:
Affected products:
xmall
Related links:
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.

