Weitong Mall
cpe:2.3:a:fuyanglipengjun:wetong_mall:*:*:*:*:*:*:*
- 1.0.0
A critical vulnerability exists in Weitong Mall version 1.0.0, specifically within the Product Statistics Handler component. The issue arises in the /queryTotal endpoint, where the isDelete parameter can be manipulated to bypass access controls. This vulnerability allows remote attackers to access sensitive product statistics intended for admin use only.
Exploitation of this vulnerability leads to unauthorized access to admin-only product statistics.
To reproduce this vulnerability, send a POST request to the /api/goods/queryTotal endpoint. Include a body with the isDelete parameter set to 1. The absence of server-side validation allows access to restricted product statistics.
It is recommended to implement strict role-based access controls on sensitive parameters like isDelete to prevent unauthorized data access.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.