{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/supermarket-1.0.0.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:zongxr:supermarket:1.0.0.0:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-103536"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Supermarket (1.0.0.0)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["ZongXR"],"content_html":"\u003cp\u003eA critical authentication vulnerability exists in ZongXR Supermarket version 1.0.0.0, specifically within the OrderController.addOrder function located in the file order/src/main/java/com/supermarket/order/controller/OrderController.java. The vulnerability manifests in the 'save' endpoint, where improper validation of the 'userId' argument allows remote attackers to bypass authentication mechanisms. Because the application fails to verify the identity of the user submitting the order, an attacker can manipulate orders on behalf of other users. Proof-of-concept exploit code is publicly available, increasing the risk of exploitation by unauthorized actors. As of the reporting date, the maintainers of the ZongXR Supermarket project have not responded to the vulnerability report, and no official patch is available. Defenders should restrict access to the affected web application endpoints.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows unauthorized users to perform order manipulation, potentially leading to financial fraud, unauthorized data access, and compromise of legitimate customer accounts. The flaw is remotely exploitable and currently has public exploit availability, posing a high risk to any instance of ZongXR Supermarket 1.0.0.0 exposed to the internet.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMonitor web server access logs for anomalous POST requests to the /save endpoint containing non-standard or unexpected 'userId' values.\u003c/li\u003e\n\u003cli\u003eImplement strict network-level access controls to restrict exposure of the ZongXR Supermarket application to known, trusted management IPs until a patch is released.\u003c/li\u003e\n\u003cli\u003eDeploy Web Application Firewall (WAF) rules to inspect the 'userId' parameter in POST requests to ensure only authorized numeric or session-validated identifiers are accepted.\u003c/li\u003e\n\u003cli\u003ePrioritize the isolation of the affected service, as the maintainers have not yet addressed the reported issue.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-01T06:38:58Z","date_published":"2026-10-01T06:38:58Z","id":"https://feed.craftedsignal.io/briefs/2026-10-zongxr-auth-bypass/","summary":"ZongXR Supermarket version 1.0.0.0 contains an authentication bypass vulnerability in the OrderController.addOrder function, enabling remote unauthorized order manipulation via the userId parameter.","title":"Authentication Bypass in ZongXR Supermarket via OrderController","url":"https://feed.craftedsignal.io/briefs/2026-10-zongxr-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Supermarket (1.0.0.0)","version":"https://jsonfeed.org/version/1.1"}