PT-2026-6933 · Unknown · Macrozheng Mall

Lennon Chia

·

Publicado

2026-02-07

·

Atualizado

2026-03-05

·

CVE-2026-25858

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions macrozheng mall versions prior to 1.0.4
Description The software contains an authentication issue in the password reset process. An unauthenticated attacker can reset user account passwords using only a victim’s telephone number. The one-time password (OTP) is exposed in the API response and password reset requests are validated by comparing the provided OTP to a value stored by telephone number, without verifying user identity or ownership of the telephone number. This allows for remote account takeover of any user with a known or guessable telephone number. The vulnerable API endpoint is the password reset flow within the mall-portal. The vulnerability exploits the lack of verification of user identity and telephone number ownership during password reset requests.
Recommendations Update macrozheng mall to version 1.0.4 or later.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-25858

Produtos afetados

Macrozheng Mall