Vendor
Tacomall 1.0.0 is vulnerable to an improper authorization flaw in the OrgStaffServiceImpl.add function, allowing remote attackers to manipulate isAdmin or jobId arguments to achieve unauthorized access.