CVE-2026-19361
LOW
2,9
Source: [email protected]
Attack Vector: network
Attack Complexity: high
Privileges Required: none
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A
LOW
3,7
Source: [email protected]
Attack Vector: network
Attack Complexity: high
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: none
Integrity: low
Availability: none
LOW
2,6
Source: [email protected]
Access Vector: network
Access Complexity: high
Authentication: none
Confidentiality: none
Integrity: partial
Availability: none
Description
AI Translation Available
A flaw has been found in macrozheng mall 0504e86. This vulnerability affects unknown code of the file /sso/getAuthCode of the component mall-portal Module. Executing a manipulation can lead to weak password recovery. The attack may be launched remotely. This attack is characterized by high complexity. It is stated that the exploitability is difficult. The exploit has been published and may be used. The vendor deleted the GitHub issue for this vulnerability without any explanation. Afterwards the vendor was contacted early about this disclosure via email but did not respond in any way.
EPSS (Exploit Prediction Scoring System)
Trend Analysis
EPSS (Exploit Prediction Scoring System)
Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.
EPSS Score
0,0028
Percentile
0,2th
Updated
EPSS Score Trend (Last 2 Days)
640
Weak Password Recovery Mechanism for Forgotten Password
IncompleteCommon Consequences
Security Scopes Affected:
Access Control
Availability
Integrity
Other
Potential Impacts:
Gain Privileges Or Assume Identity
Dos: Resource Consumption (Other)
Other
Applicable Platforms
All platforms may be affected
https://github.com/macrozheng/mall/
https://github.com/macrozheng/mall/issues/979
https://github.com/wr0ld/macrozheng-mall-Commit-0504e86-Broken-Authentication/i…
https://vuldb.com/cve/CVE-2026-19361
https://vuldb.com/submit/866081
https://vuldb.com/vuln/387215
https://vuldb.com/vuln/387215/cti