PT-2025-16382 · Unknown · Erick Xmall

Haoran Zhao

+2

·

Published

2025-04-15

·

Updated

2025-04-25

·

CVE-2025-28399

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Erick xmall versions 1.1 and earlier
Description An issue in Erick xmall allows a remote attacker to escalate privileges via the updateAddress method of the Address Controller class.
Recommendations For Erick xmall versions 1.1 and earlier, consider disabling the updateAddress method of the Address Controller class as a temporary workaround until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

LPE

Improper Privilege Management

Weakness Enumeration

Related Identifiers

CVE-2025-28399

Affected Products

Erick Xmall