PT-2025-46830 · Unknown+1 · Mall-Swarm+1

Huangweigang

·

Published

2025-11-13

·

Updated

2025-11-25

·

CVE-2025-13117

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions macrozheng mall-swarm and mall versions up to 1.0.3
Description A security issue exists due to improper authorization. This occurs through manipulation of the orderId argument within the cancelOrder function located in the file /order/cancelOrder. The attack can be initiated remotely. The exploit for this issue has been publicly disclosed. The vendor was informed of the disclosure but did not provide a response.
Recommendations Versions prior to 1.0.3 are vulnerable. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Authorization

Incorrect Privilege Assignment

Weakness Enumeration

Related Identifiers

CVE-2025-13117

Affected Products

Mall
Mall-Swarm