No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 01 Oct 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security flaw has been discovered in ZongXR SuperMarket 1.0.0.0. Affected by this issue is the function OrderController.deleteOrder of the file order/src/main/java/com/supermarket/order/controller/OrderController.java of the component Order Deletion Endpoint. Performing a manipulation of the argument orderId results in missing authentication. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. | |
| Title | ZongXR SuperMarket Order Deletion Endpoint OrderController.java OrderController.deleteOrder missing authentication | |
| First Time appeared |
Zongxr
Zongxr supermarket |
|
| Weaknesses | CWE-287 CWE-306 |
|
| CPEs | cpe:2.3:a:zongxr:supermarket:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Zongxr
Zongxr supermarket |
|
| References |
| |
| Metrics |
cvssV2_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-10-01T04:30:11.829Z
Reserved: 2026-09-30T19:07:18.677Z
Link: CVE-2026-103538
No data.
Status : Received
Published: 2026-10-01T05:17:08.450
Modified: 2026-10-01T05:17:08.450
Link: CVE-2026-103538
No data.
OpenCVE Enrichment
Updated: 2026-10-01T06:30:01Z