CVE-2026-105573: medium-severity vulnerability in newbee-ltd newbee-mall
newbee-ltd newbee-mall Shopping Cart Quantity updateAccountHeadAndDetail logic error
Published
33Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 5.3epss 0.2%
exploitation probability
0.2%top 87% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
A vulnerability was found in newbee-ltd newbee-mall up to 2.7.5. This impacts an unknown function of the file /jshERP-boot/accountHead/updateAccountHeadAndDetail of the component Shopping Cart Quantity Handler. Performing a manipulation of the argument goodsCount results in business logic errors. The attack can be initiated remotely. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P
Affected products
newbee-ltd · newbee-mallpublic PoCs found — 1
cve_referencegithub.com/newbee-ltd/newbee-mall/issues/127unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Related CVEs — newbee-ltd newbee-mall
In the same product, most dangerous first.
CVE-2026-26218CRITICALnewbee-mall Default Seeded Administrator Credentials Allow Account TakeoverEPSS 0.6%CVE-2026-94045MEDIUMnewbee-ltd newbee-mall Goods Save Endpoint UploadController.java cross site scriptingEPSS 0.4%CVE-2026-2658MEDIUMnewbee-ltd newbee-mall Multiple Endpoints cross-site request forgeryEPSS 0.3%CVE-2026-26219CRITICALnewbee-mall Unsalted MD5 Password Hashing Enables Offline Credential CrackingEPSS 0.3%