---
id: CVE-2026-105573
title: A vulnerability was found in newbee-ltd newbee-mall up to 2.7.5
summary: >-
  A vulnerability was found in newbee-ltd newbee-mall up to 2.7.5. This impacts
  an unknown function of the file
  /jshERP-boot/accountHead/updateAccountHeadAndDetail of the component Shopping
  Cart Quantity Handler. Performing a manipulation …
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-840
vendor: newbee-ltd
product: newbee-mall
affected:
  - newbee-mall 2.7.0
  - newbee-mall 2.7.1
  - newbee-mall 2.7.2
  - newbee-mall 2.7.3
  - newbee-mall 2.7.4
  - newbee-mall 2.7.5
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T03:17:01.033'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-105573'
references:
  - url: 'https://github.com/newbee-ltd/newbee-mall/'
    label: cna@vuldb.com
  - url: 'https://github.com/newbee-ltd/newbee-mall/issues/127'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-105573'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/989313'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/413632'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/413632/cti'
    label: cna@vuldb.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-06T05:47:09.320Z'
---

## Overview

A vulnerability was found in newbee-ltd newbee-mall up to 2.7.5. This impacts an unknown function of the file /jshERP-boot/accountHead/updateAccountHeadAndDetail of the component Shopping Cart Quantity Handler. Performing a manipulation of the argument goodsCount results in business logic errors. The attack can be initiated remotely. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
