Search
Find a vulnerability
Search criteria
6 vulnerabilities found for Supermarket by ZongXR
CVE-2026-103539 (GCVE-0-2026-103539)
Vulnerability from nvd – Published: 2026-10-01 05:00 – Updated: 2026-10-01 05:00
VLAI
EPSS
VEX
Title
ZongXR SuperMarket Instant Buy InstantBuyController.java startBuy missing authentication
Summary
A weakness has been identified in ZongXR SuperMarket 1.0.0.0. This affects the function startBuy of the file instant-buy/src/main/java/com/supermarket/instantbuy/controller/InstantBuyController.java of the component Instant Buy. Executing a manipulation of the argument Username can lead to missing authentication. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
Severity
Assigner
References
6 references
| URL | Tags |
|---|---|
| https://vuldb.com/vuln/412349 | vdb-entrytechnical-description |
| https://vuldb.com/vuln/412349/cti | signaturepermissions-required |
| https://vuldb.com/cve/CVE-2026-103539 | third-party-advisory |
| https://vuldb.com/submit/957826 | third-party-advisory |
| https://github.com/ZongXR/SuperMarket/issues/30 | exploitissue-tracking |
| https://github.com/ZongXR/SuperMarket/ | product |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| ZongXR | SuperMarket |
Affected:
1.0.0.0
cpe:2.3:a:zongxr:supermarket:*:*:*:*:*:*:*:* |
{
"containers": {
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:zongxr:supermarket:*:*:*:*:*:*:*:*"
],
"modules": [
"Instant Buy"
],
"product": "SuperMarket",
"vendor": "ZongXR",
"versions": [
{
"status": "affected",
"version": "1.0.0.0"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "360alphalab (VulDB User)"
},
{
"lang": "en",
"type": "coordinator",
"value": "VulDB CNA Team"
}
],
"descriptions": [
{
"lang": "en",
"value": "A weakness has been identified in ZongXR SuperMarket 1.0.0.0. This affects the function startBuy of the file instant-buy/src/main/java/com/supermarket/instantbuy/controller/InstantBuyController.java of the component Instant Buy. Executing a manipulation of the argument Username can lead to missing authentication. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 5.4,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L/E:P/RL:X/RC:C",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 5.4,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L/E:P/RL:X/RC:C",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 5.5,
"vectorString": "AV:N/AC:L/Au:S/C:N/I:P/A:P/E:POC/RL:ND/RC:C",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-306",
"description": "Missing Authentication",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-287",
"description": "Improper Authentication",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T05:00:09.463Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-412349 | ZongXR SuperMarket Instant Buy InstantBuyController.java startBuy missing authentication",
"tags": [
"vdb-entry",
"technical-description"
],
"url": "https://vuldb.com/vuln/412349"
},
{
"name": "VDB-412349 | CTI Indicators (IOB, IOC, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/412349/cti"
},
{
"name": "CVE-2026-103539 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-103539"
},
{
"name": "Submit #957826 | ZongXR SuperMarket master Missing Authentication",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/957826"
},
{
"tags": [
"exploit",
"issue-tracking"
],
"url": "https://github.com/ZongXR/SuperMarket/issues/30"
},
{
"tags": [
"product"
],
"url": "https://github.com/ZongXR/SuperMarket/"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-09-30T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-09-30T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-09-30T21:12:33.000Z",
"value": "VulDB entry last update"
}
],
"title": "ZongXR SuperMarket Instant Buy InstantBuyController.java startBuy missing authentication",
"x_generator": [
"VulDB PVTS v202610"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-103539",
"datePublished": "2026-10-01T05:00:09.463Z",
"dateReserved": "2026-09-30T19:07:24.604Z",
"dateUpdated": "2026-10-01T05:00:09.463Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-103538 (GCVE-0-2026-103538)
Vulnerability from nvd – Published: 2026-10-01 04:30 – Updated: 2026-10-01 14:16
VLAI
EPSS
VEX
Title
ZongXR SuperMarket Order Deletion Endpoint OrderController.java OrderController.deleteOrder missing authentication
Summary
A security flaw has been discovered in ZongXR SuperMarket 1.0.0.0. Affected by this issue is the function OrderController.deleteOrder of the file order/src/main/java/com/supermarket/order/controller/OrderController.java of the component Order Deletion Endpoint. Performing a manipulation of the argument orderId results in missing authentication. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
Severity
SSVC
Exploitation: poc
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-01 14:15 UTC
Assigner
References
6 references
| URL | Tags |
|---|---|
| https://vuldb.com/vuln/412348 | vdb-entrytechnical-description |
| https://vuldb.com/vuln/412348/cti | signaturepermissions-required |
| https://vuldb.com/cve/CVE-2026-103538 | third-party-advisory |
| https://vuldb.com/submit/957825 | third-party-advisory |
| https://github.com/ZongXR/SuperMarket/issues/31 | exploitissue-tracking |
| https://github.com/ZongXR/SuperMarket/ | product |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| ZongXR | SuperMarket |
Affected:
1.0.0.0
cpe:2.3:a:zongxr:supermarket:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-103538",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T14:15:48.796370Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T14:16:00.889Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:zongxr:supermarket:*:*:*:*:*:*:*:*"
],
"modules": [
"Order Deletion Endpoint"
],
"product": "SuperMarket",
"vendor": "ZongXR",
"versions": [
{
"status": "affected",
"version": "1.0.0.0"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "360alphalab (VulDB User)"
},
{
"lang": "en",
"type": "coordinator",
"value": "VulDB CNA Team"
}
],
"descriptions": [
{
"lang": "en",
"value": "A security flaw has been discovered in ZongXR SuperMarket 1.0.0.0. Affected by this issue is the function OrderController.deleteOrder of the file order/src/main/java/com/supermarket/order/controller/OrderController.java of the component Order Deletion Endpoint. Performing a manipulation of the argument orderId results in missing authentication. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 6.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:P/RL:X/RC:C",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:P/RL:X/RC:C",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 6.4,
"vectorString": "AV:N/AC:L/Au:N/C:N/I:P/A:P/E:POC/RL:ND/RC:C",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-306",
"description": "Missing Authentication",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-287",
"description": "Improper Authentication",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T04:30:11.829Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-412348 | ZongXR SuperMarket Order Deletion Endpoint OrderController.java OrderController.deleteOrder missing authentication",
"tags": [
"vdb-entry",
"technical-description"
],
"url": "https://vuldb.com/vuln/412348"
},
{
"name": "VDB-412348 | CTI Indicators (IOB, IOC, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/412348/cti"
},
{
"name": "CVE-2026-103538 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-103538"
},
{
"name": "Submit #957825 | ZongXR SuperMarket master Missing Authentication",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/957825"
},
{
"tags": [
"exploit",
"issue-tracking"
],
"url": "https://github.com/ZongXR/SuperMarket/issues/31"
},
{
"tags": [
"product"
],
"url": "https://github.com/ZongXR/SuperMarket/"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-09-30T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-09-30T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-09-30T21:12:27.000Z",
"value": "VulDB entry last update"
}
],
"title": "ZongXR SuperMarket Order Deletion Endpoint OrderController.java OrderController.deleteOrder missing authentication",
"x_generator": [
"VulDB PVTS v202610"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-103538",
"datePublished": "2026-10-01T04:30:11.829Z",
"dateReserved": "2026-09-30T19:07:18.677Z",
"dateUpdated": "2026-10-01T14:16:00.889Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-103536 (GCVE-0-2026-103536)
Vulnerability from nvd – Published: 2026-10-01 04:15 – Updated: 2026-10-01 19:09
VLAI
EPSS
VEX
Title
ZongXR Supermarket save Endpoint OrderController.java OrderController.addOrder missing authentication
Summary
A vulnerability was identified in ZongXR Supermarket 1.0.0.0. Affected by this vulnerability is the function OrderController.addOrder of the file order/src/main/java/com/supermarket/order/controller/OrderController.java of the component save Endpoint. Such manipulation of the argument userId leads to missing authentication. The attack can be executed remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.
Severity
SSVC
Exploitation: poc
Automatable: yes
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-01 19:08 UTC
Assigner
References
6 references
| URL | Tags |
|---|---|
| https://vuldb.com/vuln/412347 | vdb-entrytechnical-description |
| https://vuldb.com/vuln/412347/cti | signaturepermissions-required |
| https://vuldb.com/cve/CVE-2026-103536 | third-party-advisory |
| https://vuldb.com/submit/957824 | third-party-advisory |
| https://github.com/ZongXR/SuperMarket/issues/32 | exploitissue-tracking |
| https://github.com/ZongXR/SuperMarket/ | product |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| ZongXR | Supermarket |
Affected:
1.0.0.0
cpe:2.3:a:zongxr:supermarket:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-103536",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T19:08:38.108441Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T19:09:19.697Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:zongxr:supermarket:*:*:*:*:*:*:*:*"
],
"modules": [
"save Endpoint"
],
"product": "Supermarket",
"vendor": "ZongXR",
"versions": [
{
"status": "affected",
"version": "1.0.0.0"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "360alphalab (VulDB User)"
},
{
"lang": "en",
"type": "coordinator",
"value": "VulDB CNA Team"
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability was identified in ZongXR Supermarket 1.0.0.0. Affected by this vulnerability is the function OrderController.addOrder of the file order/src/main/java/com/supermarket/order/controller/OrderController.java of the component save Endpoint. Such manipulation of the argument userId leads to missing authentication. The attack can be executed remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 6.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 7.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 7.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 7.5,
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:C",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-306",
"description": "Missing Authentication",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-287",
"description": "Improper Authentication",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T04:15:10.029Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-412347 | ZongXR Supermarket save Endpoint OrderController.java OrderController.addOrder missing authentication",
"tags": [
"vdb-entry",
"technical-description"
],
"url": "https://vuldb.com/vuln/412347"
},
{
"name": "VDB-412347 | CTI Indicators (IOB, IOC, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/412347/cti"
},
{
"name": "CVE-2026-103536 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-103536"
},
{
"name": "Submit #957824 | ZongXR SuperMarket master Missing Authentication",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/957824"
},
{
"tags": [
"exploit",
"issue-tracking"
],
"url": "https://github.com/ZongXR/SuperMarket/issues/32"
},
{
"tags": [
"product"
],
"url": "https://github.com/ZongXR/SuperMarket/"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-09-30T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-09-30T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-09-30T21:12:20.000Z",
"value": "VulDB entry last update"
}
],
"title": "ZongXR Supermarket save Endpoint OrderController.java OrderController.addOrder missing authentication",
"x_generator": [
"VulDB PVTS v202610"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-103536",
"datePublished": "2026-10-01T04:15:10.029Z",
"dateReserved": "2026-09-30T19:07:13.098Z",
"dateUpdated": "2026-10-01T19:09:19.697Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-103539 (GCVE-0-2026-103539)
Vulnerability from cvelistv5 – Published: 2026-10-01 05:00 – Updated: 2026-10-01 05:00
VLAI
EPSS
VEX
Title
ZongXR SuperMarket Instant Buy InstantBuyController.java startBuy missing authentication
Summary
A weakness has been identified in ZongXR SuperMarket 1.0.0.0. This affects the function startBuy of the file instant-buy/src/main/java/com/supermarket/instantbuy/controller/InstantBuyController.java of the component Instant Buy. Executing a manipulation of the argument Username can lead to missing authentication. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
Severity
Assigner
References
6 references
| URL | Tags |
|---|---|
| https://vuldb.com/vuln/412349 | vdb-entrytechnical-description |
| https://vuldb.com/vuln/412349/cti | signaturepermissions-required |
| https://vuldb.com/cve/CVE-2026-103539 | third-party-advisory |
| https://vuldb.com/submit/957826 | third-party-advisory |
| https://github.com/ZongXR/SuperMarket/issues/30 | exploitissue-tracking |
| https://github.com/ZongXR/SuperMarket/ | product |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| ZongXR | SuperMarket |
Affected:
1.0.0.0
cpe:2.3:a:zongxr:supermarket:*:*:*:*:*:*:*:* |
{
"containers": {
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:zongxr:supermarket:*:*:*:*:*:*:*:*"
],
"modules": [
"Instant Buy"
],
"product": "SuperMarket",
"vendor": "ZongXR",
"versions": [
{
"status": "affected",
"version": "1.0.0.0"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "360alphalab (VulDB User)"
},
{
"lang": "en",
"type": "coordinator",
"value": "VulDB CNA Team"
}
],
"descriptions": [
{
"lang": "en",
"value": "A weakness has been identified in ZongXR SuperMarket 1.0.0.0. This affects the function startBuy of the file instant-buy/src/main/java/com/supermarket/instantbuy/controller/InstantBuyController.java of the component Instant Buy. Executing a manipulation of the argument Username can lead to missing authentication. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 5.4,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L/E:P/RL:X/RC:C",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 5.4,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L/E:P/RL:X/RC:C",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 5.5,
"vectorString": "AV:N/AC:L/Au:S/C:N/I:P/A:P/E:POC/RL:ND/RC:C",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-306",
"description": "Missing Authentication",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-287",
"description": "Improper Authentication",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T05:00:09.463Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-412349 | ZongXR SuperMarket Instant Buy InstantBuyController.java startBuy missing authentication",
"tags": [
"vdb-entry",
"technical-description"
],
"url": "https://vuldb.com/vuln/412349"
},
{
"name": "VDB-412349 | CTI Indicators (IOB, IOC, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/412349/cti"
},
{
"name": "CVE-2026-103539 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-103539"
},
{
"name": "Submit #957826 | ZongXR SuperMarket master Missing Authentication",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/957826"
},
{
"tags": [
"exploit",
"issue-tracking"
],
"url": "https://github.com/ZongXR/SuperMarket/issues/30"
},
{
"tags": [
"product"
],
"url": "https://github.com/ZongXR/SuperMarket/"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-09-30T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-09-30T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-09-30T21:12:33.000Z",
"value": "VulDB entry last update"
}
],
"title": "ZongXR SuperMarket Instant Buy InstantBuyController.java startBuy missing authentication",
"x_generator": [
"VulDB PVTS v202610"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-103539",
"datePublished": "2026-10-01T05:00:09.463Z",
"dateReserved": "2026-09-30T19:07:24.604Z",
"dateUpdated": "2026-10-01T05:00:09.463Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-103538 (GCVE-0-2026-103538)
Vulnerability from cvelistv5 – Published: 2026-10-01 04:30 – Updated: 2026-10-01 14:16
VLAI
EPSS
VEX
Title
ZongXR SuperMarket Order Deletion Endpoint OrderController.java OrderController.deleteOrder missing authentication
Summary
A security flaw has been discovered in ZongXR SuperMarket 1.0.0.0. Affected by this issue is the function OrderController.deleteOrder of the file order/src/main/java/com/supermarket/order/controller/OrderController.java of the component Order Deletion Endpoint. Performing a manipulation of the argument orderId results in missing authentication. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
Severity
SSVC
Exploitation: poc
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-01 14:15 UTC
Assigner
References
6 references
| URL | Tags |
|---|---|
| https://vuldb.com/vuln/412348 | vdb-entrytechnical-description |
| https://vuldb.com/vuln/412348/cti | signaturepermissions-required |
| https://vuldb.com/cve/CVE-2026-103538 | third-party-advisory |
| https://vuldb.com/submit/957825 | third-party-advisory |
| https://github.com/ZongXR/SuperMarket/issues/31 | exploitissue-tracking |
| https://github.com/ZongXR/SuperMarket/ | product |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| ZongXR | SuperMarket |
Affected:
1.0.0.0
cpe:2.3:a:zongxr:supermarket:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-103538",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T14:15:48.796370Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T14:16:00.889Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:zongxr:supermarket:*:*:*:*:*:*:*:*"
],
"modules": [
"Order Deletion Endpoint"
],
"product": "SuperMarket",
"vendor": "ZongXR",
"versions": [
{
"status": "affected",
"version": "1.0.0.0"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "360alphalab (VulDB User)"
},
{
"lang": "en",
"type": "coordinator",
"value": "VulDB CNA Team"
}
],
"descriptions": [
{
"lang": "en",
"value": "A security flaw has been discovered in ZongXR SuperMarket 1.0.0.0. Affected by this issue is the function OrderController.deleteOrder of the file order/src/main/java/com/supermarket/order/controller/OrderController.java of the component Order Deletion Endpoint. Performing a manipulation of the argument orderId results in missing authentication. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 6.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:P/RL:X/RC:C",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:P/RL:X/RC:C",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 6.4,
"vectorString": "AV:N/AC:L/Au:N/C:N/I:P/A:P/E:POC/RL:ND/RC:C",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-306",
"description": "Missing Authentication",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-287",
"description": "Improper Authentication",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T04:30:11.829Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-412348 | ZongXR SuperMarket Order Deletion Endpoint OrderController.java OrderController.deleteOrder missing authentication",
"tags": [
"vdb-entry",
"technical-description"
],
"url": "https://vuldb.com/vuln/412348"
},
{
"name": "VDB-412348 | CTI Indicators (IOB, IOC, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/412348/cti"
},
{
"name": "CVE-2026-103538 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-103538"
},
{
"name": "Submit #957825 | ZongXR SuperMarket master Missing Authentication",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/957825"
},
{
"tags": [
"exploit",
"issue-tracking"
],
"url": "https://github.com/ZongXR/SuperMarket/issues/31"
},
{
"tags": [
"product"
],
"url": "https://github.com/ZongXR/SuperMarket/"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-09-30T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-09-30T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-09-30T21:12:27.000Z",
"value": "VulDB entry last update"
}
],
"title": "ZongXR SuperMarket Order Deletion Endpoint OrderController.java OrderController.deleteOrder missing authentication",
"x_generator": [
"VulDB PVTS v202610"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-103538",
"datePublished": "2026-10-01T04:30:11.829Z",
"dateReserved": "2026-09-30T19:07:18.677Z",
"dateUpdated": "2026-10-01T14:16:00.889Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-103536 (GCVE-0-2026-103536)
Vulnerability from cvelistv5 – Published: 2026-10-01 04:15 – Updated: 2026-10-01 19:09
VLAI
EPSS
VEX
Title
ZongXR Supermarket save Endpoint OrderController.java OrderController.addOrder missing authentication
Summary
A vulnerability was identified in ZongXR Supermarket 1.0.0.0. Affected by this vulnerability is the function OrderController.addOrder of the file order/src/main/java/com/supermarket/order/controller/OrderController.java of the component save Endpoint. Such manipulation of the argument userId leads to missing authentication. The attack can be executed remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.
Severity
SSVC
Exploitation: poc
Automatable: yes
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-01 19:08 UTC
Assigner
References
6 references
| URL | Tags |
|---|---|
| https://vuldb.com/vuln/412347 | vdb-entrytechnical-description |
| https://vuldb.com/vuln/412347/cti | signaturepermissions-required |
| https://vuldb.com/cve/CVE-2026-103536 | third-party-advisory |
| https://vuldb.com/submit/957824 | third-party-advisory |
| https://github.com/ZongXR/SuperMarket/issues/32 | exploitissue-tracking |
| https://github.com/ZongXR/SuperMarket/ | product |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| ZongXR | Supermarket |
Affected:
1.0.0.0
cpe:2.3:a:zongxr:supermarket:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-103536",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T19:08:38.108441Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T19:09:19.697Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:zongxr:supermarket:*:*:*:*:*:*:*:*"
],
"modules": [
"save Endpoint"
],
"product": "Supermarket",
"vendor": "ZongXR",
"versions": [
{
"status": "affected",
"version": "1.0.0.0"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "360alphalab (VulDB User)"
},
{
"lang": "en",
"type": "coordinator",
"value": "VulDB CNA Team"
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability was identified in ZongXR Supermarket 1.0.0.0. Affected by this vulnerability is the function OrderController.addOrder of the file order/src/main/java/com/supermarket/order/controller/OrderController.java of the component save Endpoint. Such manipulation of the argument userId leads to missing authentication. The attack can be executed remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 6.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 7.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 7.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 7.5,
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:C",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-306",
"description": "Missing Authentication",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-287",
"description": "Improper Authentication",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T04:15:10.029Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-412347 | ZongXR Supermarket save Endpoint OrderController.java OrderController.addOrder missing authentication",
"tags": [
"vdb-entry",
"technical-description"
],
"url": "https://vuldb.com/vuln/412347"
},
{
"name": "VDB-412347 | CTI Indicators (IOB, IOC, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/412347/cti"
},
{
"name": "CVE-2026-103536 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-103536"
},
{
"name": "Submit #957824 | ZongXR SuperMarket master Missing Authentication",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/957824"
},
{
"tags": [
"exploit",
"issue-tracking"
],
"url": "https://github.com/ZongXR/SuperMarket/issues/32"
},
{
"tags": [
"product"
],
"url": "https://github.com/ZongXR/SuperMarket/"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-09-30T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-09-30T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-09-30T21:12:20.000Z",
"value": "VulDB entry last update"
}
],
"title": "ZongXR Supermarket save Endpoint OrderController.java OrderController.addOrder missing authentication",
"x_generator": [
"VulDB PVTS v202610"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-103536",
"datePublished": "2026-10-01T04:15:10.029Z",
"dateReserved": "2026-09-30T19:07:13.098Z",
"dateUpdated": "2026-10-01T19:09:19.697Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}