PT-2025-3439 · Unknown · Macrozheng Mall-Tiny
Published
2025-01-31
·
Updated
2025-09-02
·
CVE-2024-57432
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
macrozheng mall-tiny version 1.0.1
Description
The issue concerns insecure permissions in the application. Specifically, the JWT signing keys are hardcoded and do not change. User information is explicitly written into the JWT and used for subsequent privilege management. This makes it possible to forge the JWT of any user, allowing for authentication bypass.
Recommendations
For macrozheng mall-tiny version 1.0.1, consider regenerating and securely storing the JWT signing keys to prevent unauthorized access. As a temporary workaround, restrict the use of user information in the JWT to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Incorrect Authorization
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Macrozheng Mall-Tiny