Tag
An unauthenticated remote code execution vulnerability in mall4j through 4.0 allows attackers to reset arbitrary storefront passwords via the PUT /user/updatePwd endpoint.