CPE
ZongXR Supermarket version 1.0.0.0 contains an authentication bypass vulnerability in the OrderController.addOrder function, enabling remote unauthorized order manipulation via the userId parameter.