Metrics
Affected Vendors & Products
Sat, 15 Nov 2025 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security flaw has been discovered in macrozheng mall-swarm up to 1.0.3. This impacts the function detail of the file /order/detail/ of the component Order Details Handler. Performing manipulation of the argument orderId results in improper authorization. It is possible to initiate the attack remotely. The exploit has been released to the public and may be exploited. The vendor was contacted early about this disclosure but did not respond in any way. | A security flaw has been discovered in macrozheng mall-swarm and mall up to 1.0.3. This impacts the function detail of the file /order/detail/ of the component Order Details Handler. Performing manipulation of the argument orderId results in improper authorization. It is possible to initiate the attack remotely. The exploit has been released to the public and may be exploited. The vendor was contacted early about this disclosure but did not respond in any way. |
| Title | macrozheng mall-swarm Order Details detail improper authorization | macrozheng mall-swarm/mall Order Details detail improper authorization |
| References |
|
Fri, 14 Nov 2025 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Macrozheng
Macrozheng mall |
|
| Vendors & Products |
Macrozheng
Macrozheng mall |
Thu, 13 Nov 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 13 Nov 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security flaw has been discovered in macrozheng mall-swarm up to 1.0.3. This impacts the function detail of the file /order/detail/ of the component Order Details Handler. Performing manipulation of the argument orderId results in improper authorization. It is possible to initiate the attack remotely. The exploit has been released to the public and may be exploited. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | macrozheng mall-swarm Order Details detail improper authorization | |
| Weaknesses | CWE-266 CWE-285 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2025-11-13T13:32:09.111Z
Updated: 2025-11-15T06:19:23.088Z
Reserved: 2025-11-13T06:56:38.626Z
Link: CVE-2025-13115
Updated: 2025-11-13T13:54:43.997Z
Status : Awaiting Analysis
Published: 2025-11-13T14:15:48.330
Modified: 2025-11-15T07:15:44.957
Link: CVE-2025-13115
No data.