PT-2025-37446 · Unknown · Newbee-Mall

Ez-Lbz

·

Published

2025-09-15

·

Updated

2025-10-14

·

CVE-2025-10423

CVSS v3.1

3.7

Low

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions newbee-mall version 1.0
Description A flaw exists within the mallKaptcha function located in the /common/mall/kaptcha file, leading to the generation of guessable CAPTCHAs. This issue can be exploited remotely and is considered difficult to exploit due to its high complexity. The exploit for this issue has been publicly disclosed.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2025-10423

Affected Products

Newbee-Mall