{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-15186","assignerOrgId":"1af790b2-7ee1-4545-860a-a788eba489b5","state":"PUBLISHED","assignerShortName":"VulDB","dateReserved":"2026-07-09T05:06:59.607Z","datePublished":"2026-07-09T13:15:08.296Z","dateUpdated":"2026-07-09T14:39:10.538Z"},"containers":{"cna":{"providerMetadata":{"orgId":"1af790b2-7ee1-4545-860a-a788eba489b5","shortName":"VulDB","dateUpdated":"2026-07-09T13:15:08.296Z"},"title":"macrozheng mall Portal Endpoint create resource injection","problemTypes":[{"descriptions":[{"type":"CWE","cweId":"CWE-99","lang":"en","description":"Improper Control of Resource Identifiers"}]}],"affected":[{"vendor":"macrozheng","product":"mall","versions":[{"version":"1.0.0","status":"affected"},{"version":"1.0.1","status":"affected"},{"version":"1.0.2","status":"affected"},{"version":"1.0.3","status":"affected"}],"cpes":["cpe:2.3:a:macrozheng:mall:*:*:*:*:*:*:*:*"],"modules":["Portal Endpoint"]}],"descriptions":[{"lang":"en","value":"A vulnerability was identified in macrozheng mall up to 1.0.3. This impacts an unknown function of the file /returnApply/create of the component Portal Endpoint. The manipulation of the argument orderId leads to improper control of resource identifiers. The attack can be initiated remotely. The exploit is publicly available and might be used. The vendor deleted the GitHub issue for this vulnerability without any explanation."}],"metrics":[{"cvssV4_0":{"version":"4.0","baseScore":5.3,"vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P","baseSeverity":"MEDIUM"}},{"cvssV3_1":{"version":"3.1","baseScore":6.3,"vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R","baseSeverity":"MEDIUM"}},{"cvssV3_0":{"version":"3.0","baseScore":6.3,"vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R","baseSeverity":"MEDIUM"}},{"cvssV2_0":{"version":"2.0","baseScore":6.5,"vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR"}}],"timeline":[{"time":"2026-07-09T00:00:00.000Z","lang":"en","value":"Advisory disclosed"},{"time":"2026-07-09T02:00:00.000Z","lang":"en","value":"VulDB entry created"},{"time":"2026-07-09T07:12:10.000Z","lang":"en","value":"VulDB entry last update"}],"credits":[{"lang":"en","value":"peanutbutter (VulDB User)","type":"reporter"},{"lang":"en","value":"VulDB CNA Team","type":"coordinator"}],"references":[{"url":"https://vuldb.com/vuln/377112","name":"VDB-377112 | macrozheng mall Portal Endpoint create resource injection","tags":["vdb-entry","technical-description"]},{"url":"https://vuldb.com/vuln/377112/cti","name":"VDB-377112 | CTI Indicators (IOB, IOC, IOA)","tags":["signature","permissions-required"]},{"url":"https://vuldb.com/cve/CVE-2026-15186","name":"CVE-2026-15186 | CVE Analysis and Report","tags":["third-party-advisory"]},{"url":"https://vuldb.com/submit/851347","name":"Submit #851347 | macrozheng mall 1.0.3 Insecure Direct Object Reference","tags":["third-party-advisory"]},{"url":"https://github.com/macrozheng/mall/issues/977","tags":["issue-tracking"]},{"url":"https://github.com/macrozheng/mall/","tags":["product"]}]},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-07-09T13:35:42.603352Z","id":"CVE-2026-15186","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-07-09T14:39:10.538Z"}}]}}