PT-2025-3439 · Unknown · Macrozheng Mall-Tiny

Published

2025-01-31

·

Updated

2025-09-02

·

CVE-2024-57432

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions macrozheng mall-tiny version 1.0.1
Description The issue concerns insecure permissions in the application. Specifically, the JWT signing keys are hardcoded and do not change. User information is explicitly written into the JWT and used for subsequent privilege management. This makes it possible to forge the JWT of any user, allowing for authentication bypass.
Recommendations For macrozheng mall-tiny version 1.0.1, consider regenerating and securely storing the JWT signing keys to prevent unauthorized access. As a temporary workaround, restrict the use of user information in the JWT to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Incorrect Authorization

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-57432

Affected Products

Macrozheng Mall-Tiny