CVE-2026-108784 | macrozheng mall up to 1.0.3 Payment Endpoint AlipayServiceImpl.java AlipayServiceImpl.pay total_amount logic error (Issue 998)
A vulnerability was found in macrozheng mall up to 1.0.3. It has been declared as critical. This vulnerability affects the function AlipayServiceImpl.pay of the file com/macro/mall/portal/service/impl/AlipayServiceImpl.java of the component Payment Endpoint. The manipulation of the argument total_amount results in business logic errors.
This vulnerability is reported as CVE-2026-108784. The attack can be launched remotely. Moreover, an exploit is present.
A patch should be applied to remediate this issue.VulDB Recent EntriesRead More