CVE-2026-103539: ZongXR SuperMarket Instant Buy InstantBuyController.java startBuy missing authentication
A weakness has been identified in ZongXR SuperMarket 1.0.0.0. This affects the function startBuy of the file instant-buy/src/main/java/com/supermarket/instantbuy/controller/InstantBuyController.java of the component Instant Buy. Executing a manipulation of the argument Username can lead to missing authentication. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
Affected Software
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The attack can be performed remotely and requires low privileges. No user interaction is required.
What input is involved in the authentication bypass?
The issue is triggered by manipulating the Username argument handled by the startBuy function in InstantBuyController.java.
Which deployments are known to be affected?
The affected product version identified is ZongXR SuperMarket Instant Buy 1.0.0.0, specifically the Instant Buy component.
How urgent is remediation?
A public exploit is available and may be used in attacks. The issue has a medium severity score of 5.4, with potential integrity and availability impact.
Is a vendor fix available?
The provided information does not identify a fix. It states that the project was notified through an issue report but had not responded.