Beveiligingsadvies

CVE-2025-9836

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2025-09-02 22:02:07
Laatst bijgewerkt 2025-09-03 20:04:41
Toegewezen door VulDB
CVSS-score 5.3
Status PUBLISHED

Beschrijving

A vulnerability was found in macrozheng mall up to 1.0.3. This vulnerability affects the function paySuccess of the file /order/paySuccess. The manipulation of the argument orderId results in authorization bypass. The attack can be launched remotely. The exploit has been made public and could be used.