PT-2026-6933 · Unknown · Macrozheng Mall
Lennon Chia
·
Publicado
2026-02-07
·
Atualizado
2026-03-05
·
CVE-2026-25858
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
macrozheng mall versions prior to 1.0.4
Description
The software contains an authentication issue in the password reset process. An unauthenticated attacker can reset user account passwords using only a victim’s telephone number. The one-time password (OTP) is exposed in the API response and password reset requests are validated by comparing the provided OTP to a value stored by telephone number, without verifying user identity or ownership of the telephone number. This allows for remote account takeover of any user with a known or guessable telephone number. The vulnerable API endpoint is the password reset flow within the
mall-portal. The vulnerability exploits the lack of verification of user identity and telephone number ownership during password reset requests.Recommendations
Update macrozheng mall to version 1.0.4 or later.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Macrozheng Mall