A vulnerability, which was classified as problematic, was found in Tmall Demo up to 20250505. This affects an unknown part of the file /tmall/order/pay/ of the component Payment Identifier Handler. The manipulation leads to insufficiently random values. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The vendor was contacted early about this disclosure but did not respond in any way.
History

Thu, 19 Jun 2025 01:00:00 +0000

Type Values Removed Values Added
First Time appeared Project Team
Project Team tmall Demo
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:project_team:tmall_demo:*:*:*:*:*:*:*:*
Vendors & Products Project Team
Project Team tmall Demo

Wed, 28 May 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 24 May 2025 23:45:00 +0000

Type Values Removed Values Added
Description A vulnerability, which was classified as problematic, was found in Tmall Demo up to 20250505. This affects an unknown part of the file /tmall/order/pay/ of the component Payment Identifier Handler. The manipulation leads to insufficiently random values. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The vendor was contacted early about this disclosure but did not respond in any way.
Title Tmall Demo Payment Identifier pay random values
Weaknesses CWE-310
CWE-330
References
Metrics cvssV2_0

{'score': 2.6, 'vector': 'AV:N/AC:H/Au:N/C:P/I:N/A:N'}

cvssV3_0

{'score': 3.7, 'vector': 'CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N'}

cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2025-05-24T23:31:04.556Z

Updated: 2025-05-28T17:39:25.386Z

Reserved: 2025-05-23T18:41:48.704Z

Link: CVE-2025-5136

cve-icon Vulnrichment

Updated: 2025-05-27T14:22:33.772Z

cve-icon NVD

Status : Analyzed

Published: 2025-05-25T00:15:23.043

Modified: 2025-06-19T00:43:40.970

Link: CVE-2025-5136

cve-icon Redhat

No data.