CVE-2026-105573: fallo de gravedad media en newbee-ltd newbee-mall
newbee-ltd newbee-mall Shopping Cart Quantity updateAccountHeadAndDetail logic error
Publicada el
33Vexday Risk Score
Sin señal de explotación. Ella tiene prueba de concepto pública.
ssvc Attendcvss 5.3epss 0.2%
probabilidad de explotación
0.2%top 87% de las CVE
explotación observada
noninguna fuente lo reporta
1 exploit(s) público(s)
A vulnerability was found in newbee-ltd newbee-mall up to 2.7.5. This impacts an unknown function of the file /jshERP-boot/accountHead/updateAccountHeadAndDetail of the component Shopping Cart Quantity Handler. Performing a manipulation of the argument goodsCount results in business logic errors. The attack can be initiated remotely. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P
Productos afectados
newbee-ltd · newbee-mallPoCs públicas encontradas — 1
cve_referencegithub.com/newbee-ltd/newbee-mall/issues/127no verificado⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.
CVEs relacionadas — newbee-ltd newbee-mall
En el mismo producto, de las más peligrosas a las menos.
CVE-2026-26218CRITICALnewbee-mall Default Seeded Administrator Credentials Allow Account TakeoverEPSS 0.6%CVE-2026-94045MEDIUMnewbee-ltd newbee-mall Goods Save Endpoint UploadController.java cross site scriptingEPSS 0.4%CVE-2026-2658MEDIUMnewbee-ltd newbee-mall Multiple Endpoints cross-site request forgeryEPSS 0.3%CVE-2026-26219CRITICALnewbee-mall Unsalted MD5 Password Hashing Enables Offline Credential CrackingEPSS 0.3%