CVE-2026-103539 | ZongXR SuperMarket 1.0.0.0 Instant Buy InstantBuyController.java startBuy userName missing authentication (Issue 30)
A vulnerability was found in ZongXR SuperMarket 1.0.0.0. It has been declared as problematic. This affects the function startBuy of the file instant-buy/src/main/java/com/supermarket/instantbuy/controller/InstantBuyController.java of the component Instant Buy. Executing a manipulation of the argument Username can lead to missing authentication.
This vulnerability appears as CVE-2026-103539. The attack may be performed from remote. In addition, an exploit is available.
The project was informed of the problem early through an issue report but has not responded yet.VulDB Recent EntriesRead More