CVE-2026-102361 | gz-yami mall4j up to 4.0 Password Reset /user/updatePwd Username missing authentication
A vulnerability classified as critical has been found in gz-yami mall4j up to 4.0. This affects the function updatePwd of the file /user/updatePwd of the component Password Reset. The manipulation of the argument Username leads to missing authentication.
This vulnerability is documented as CVE-2026-102361. The attack can be initiated remotely. There is not any exploit available.VulDB Recent EntriesRead More