Vulnerabilities
CVE-2023-36331 - Xmall Unauthenticated Order Details Disclosure Vulnerability (2026)
2026-01-12
0 views
admin
CVE ID : CVE-2023-36331 Published : Jan. 12, 2026, 8:15 p.m. | 30 minutes ago Description : Incorrect access control in the /member/orderList API of xmall v1.1 allows attackers to arbitrarily access other users' order details via manipulation of the query parameter userId. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE Details
CVE ID
Published
Jan. 12, 2026
🏷️ Tags
36331xmallunauthenticatedorderdetailsdisclosurevulnerabilitypublishedcve
More from Vulnerabilities
Report: Essential Guide: CVE-2026-41268 - Flowise: Flowise Parameter Override Bypass Remote Command Execution
2026-04-23
0
Report: Complete Guide to CVE-2026-31168 - ToToLink A3300R Command Injection Vulnerability
2026-04-23
0
Report: CVE-2026-31167 - ToToLink A3300R Command Injection Vulnerability - Analysis
2026-04-23
0
Report: CVE-2026-31166 - ToToLink A3300R Command Injection Vulnerability
2026-04-23
0
Trending
1
CVE-2025-61481: Critical Remote Code Execution Vulnerability in MikroTik RouterOS & SwitchOS
2025-10-27 • 189 views
2
CVE-2025-43939: Dell Unity OS Command Injection (High)
2025-10-30 • 148 views
3
Google disputes false claims of massive Gmail data breach
2025-10-30 • 130 views
4
Microsoft: DNS outage impacts Azure and Microsoft 365 services
2025-10-30 • 88 views
5
3.5B Accounts, 1 Critical Flaw: Meta Closes WhatsApp Data-Harvesting
2025-11-25 • 81 views