Skip to main content
// menu
×
>
Loading…
// threat_lookup
×
☰
INTELLIGENCE ROOM
// cybersoc_platform
Dashboard
CVE/RCE
APT
News
Reports
Pulse
SOON
Graph
SOON
Market
SOON
Playback
SOON
NOMINAL
0
Sign in
Join →
CVE-2023-36331 — Incorrect access control in the /member/orderList API of xmall v1.1 allows attackers to arbitrarily access other users' order details via manipulation of the query parameter userId. — CVE Database · The Intelligence Room