Weitong Mall Access Control Vulnerability in Product Statistics Handler

Vulnerability

A critical vulnerability exists in Weitong Mall version 1.0.0, specifically within the Product Statistics Handler component. The issue arises in the /queryTotal endpoint, where the isDelete parameter can be manipulated to bypass access controls. This vulnerability allows remote attackers to access sensitive product statistics intended for admin use only.

Impact

Exploitation of this vulnerability leads to unauthorized access to admin-only product statistics.

Reproduction

To reproduce this vulnerability, send a POST request to the /api/goods/queryTotal endpoint. Include a body with the isDelete parameter set to 1. The absence of server-side validation allows access to restricted product statistics.

Remediation

It is recommended to implement strict role-based access controls on sensitive parameters like isDelete to prevent unauthorized data access.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
1.0
impact
2.5
exploitability
6.8
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.