CVE-2025-9836

Publication date

2025-09-02 22:02:07

Family

VulDB

State

PUBLISHED

Description

A vulnerability was found in macrozheng mall up to 1.0.3. This vulnerability affects the function paySuccess of the file /order/paySuccess. The manipulation of the argument orderId results in authorization bypass. The attack can be launched remotely. The exploit has been made public and could be used.