Metrics
Affected Vendors & Products
Sat, 15 Nov 2025 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was detected in macrozheng mall-swarm up to 1.0.3. Affected by this issue is the function paySuccess of the file /order/paySuccess. The manipulation of the argument orderID results in improper authorization. The attack can be launched remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | A vulnerability was detected in macrozheng mall-swarm and mall up to 1.0.3. Affected by this issue is the function paySuccess of the file /order/paySuccess. The manipulation of the argument orderID results in improper authorization. The attack can be launched remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. |
| Title | macrozheng mall-swarm paySuccess improper authorization | macrozheng mall-swarm/mall paySuccess improper authorization |
| References |
|
Fri, 14 Nov 2025 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Macrozheng
Macrozheng mall |
|
| Vendors & Products |
Macrozheng
Macrozheng mall |
Thu, 13 Nov 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 13 Nov 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was detected in macrozheng mall-swarm up to 1.0.3. Affected by this issue is the function paySuccess of the file /order/paySuccess. The manipulation of the argument orderID results in improper authorization. The attack can be launched remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | macrozheng mall-swarm paySuccess improper authorization | |
| Weaknesses | CWE-266 CWE-285 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2025-11-13T15:02:05.419Z
Updated: 2025-11-15T06:19:32.172Z
Reserved: 2025-11-13T06:56:46.330Z
Link: CVE-2025-13118
Updated: 2025-11-13T15:33:22.491Z
Status : Awaiting Analysis
Published: 2025-11-13T15:15:50.653
Modified: 2025-11-15T07:15:45.897
Link: CVE-2025-13118
No data.