Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 01 Oct 2026 05:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A weakness has been identified in ZongXR SuperMarket 1.0.0.0. This affects the function startBuy of the file instant-buy/src/main/java/com/supermarket/instantbuy/controller/InstantBuyController.java of the component Instant Buy. Executing a manipulation of the argument Username can lead to missing authentication. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. | |
| Title | ZongXR SuperMarket Instant Buy InstantBuyController.java startBuy missing authentication | |
| First Time appeared |
Zongxr
Zongxr supermarket |
|
| Weaknesses | CWE-287 CWE-306 |
|
| CPEs | cpe:2.3:a:zongxr:supermarket:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Zongxr
Zongxr supermarket |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-10-01T05:00:09.463Z
Reserved: 2026-09-30T19:07:24.604Z
Link: CVE-2026-103539
No data.
Status : Received
Published: 2026-10-01T05:17:08.680
Modified: 2026-10-01T05:17:08.680
Link: CVE-2026-103539
No data.
OpenCVE Enrichment
Updated: 2026-10-01T07:00:03Z
