PT-2025-37443 · Unknown · Newbee-Mall

Ez-Lbz

·

Published

2025-09-15

·

Updated

2025-10-14

·

CVE-2025-10422

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions newbee-mall versions prior to 613a662adf1da7623ec34459bc83e3c1b12d8ce7
Description A vulnerability exists in newbee-mall related to improper authorization. The issue affects the paySuccess function within the /paySuccess file of the Order Status Handler component. Manipulation of the orderNo argument can lead to unauthorized access. The exploit has been publicly disclosed.
Recommendations Update newbee-mall to a version prior to 613a662adf1da7623ec34459bc83e3c1b12d8ce7. As a temporary workaround, consider restricting access to the /paySuccess file or the paySuccess function until a patch is available.

Exploit

Fix

Improper Authorization

Incorrect Privilege Assignment

Weakness Enumeration

Related Identifiers

CVE-2025-10422

Affected Products

Newbee-Mall