PT-2025-46827 · Macrozheng · Mall-Swarm+1

Huangweigang

·

Published

2025-11-13

·

Updated

2025-11-25

·

CVE-2025-13115

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions macrozheng mall-swarm versions up to 1.0.3 macrozheng mall versions up to 1.0.3
Description A security flaw exists due to improper authorization when manipulating the orderId argument in the function detail of the Order Details Handler component. This flaw is located in the file '/order/detail/'. The attack can be initiated remotely, and the exploit is publicly available. The vendor was informed of this issue but did not respond.
Recommendations Versions up to 1.0.3 should be updated.

Exploit

Fix

Improper Authorization

Incorrect Privilege Assignment

Weakness Enumeration

Related Identifiers

CVE-2025-13115

Affected Products

Mall
Mall-Swarm