CVE-2026-12204

A vulnerability was determined in ShopXO up to 6.7.1. This vulnerability affects the function OrderClose/OrderSuccess/PayLogOrderClose/GoodsGiveIntegral of the file app/api/controller/Crontab.php of the component Scheduled Task Endpoint. Executing a manipulation can lead to authorization bypass. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Configurations

No configuration.

History

23 Jul 2026, 11:10

Type Values Removed Values Added
Summary
  • (es) Se determinó una vulnerabilidad en ShopXO hasta la versión 6.7.1. Esta vulnerabilidad afecta la función OrderClose/OrderSuccess/PayLogOrderClose/GoodsGiveIntegral del archivo app/API/controller/Crontab.PHP del componente Scheduled Task Endpoint. La ejecución de una manipulación puede llevar a una omisión de autorización. El ataque puede ejecutarse de forma remota. El exploit ha sido divulgado públicamente y puede ser utilizado. Se contactó al proveedor con antelación sobre esta divulgación, pero no respondió de ninguna manera.

15 Jun 2026, 02:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-15 02:16

Updated : 2026-07-24 12:10


NVD link : CVE-2026-12204

Mitre link : CVE-2026-12204

CVE.ORG link : CVE-2026-12204


JSON object : View

Products Affected

No product.

CWE
CWE-285

Improper Authorization

CWE-639

Authorization Bypass Through User-Controlled Key