Vulnerabilities
CVE-2023-36331 - Xmall Unauthenticated Order Details Disclosure Vulnerability (2026)
2026-01-12
0 views
admin
CVE ID : CVE-2023-36331 Published : Jan. 12, 2026, 8:15 p.m. | 30 minutes ago Description : Incorrect access control in the /member/orderList API of xmall v1.1 allows attackers to arbitrarily access other users' order details via manipulation of the query parameter userId. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE Details
CVE ID
Published
Jan. 12, 2026
🏷️ Tags
36331xmallunauthenticatedorderdetailsdisclosurevulnerabilitypublishedcve
More from Vulnerabilities
Report: Essential Guide: CVE-2026-25720 - SenseLive X3050 Insufficient session expiration
2026-04-24
0
Report: CVE-2026-1789 - Xerox Printer Information Disclosure Vulnerability - Full Analysis
2026-04-24
0
Report: Update: CVE-2026-35064 - SenseLive X3050 Missing authentication for critical function
2026-04-24
0
Report: Complete Guide to CVE-2026-31952 - Xibo CMS API has SQL Injection via DataSet Filter Parameter
2026-04-24
0
Trending
1
CVE-2025-61481: Critical Remote Code Execution Vulnerability in MikroTik RouterOS & SwitchOS
2025-10-27 • 189 views
2
CVE-2025-43939: Dell Unity OS Command Injection (High)
2025-10-30 • 148 views
3
Google disputes false claims of massive Gmail data breach
2025-10-30 • 130 views
4
Microsoft: DNS outage impacts Azure and Microsoft 365 services
2025-10-30 • 88 views
5
3.5B Accounts, 1 Critical Flaw: Meta Closes WhatsApp Data-Harvesting
2025-11-25 • 81 views