PT-2025-46833 · Macrozheng · Mall-Swarm

Huangweigang

·

Published

2025-11-13

·

Updated

2026-05-23

·

CVE-2025-13118

CVSS v3.1

6.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions macrozheng mall-swarm versions up to 1.0.3
Description A flaw exists in macrozheng mall-swarm that allows for remote authorization bypass due to improper authorization. The issue is related to the paySuccess function within the /order/paySuccess file. Manipulation of the orderID argument can lead to unauthorized access. The exploit is publicly available. The vendor was notified but did not respond.
Recommendations Versions prior to 1.0.3 are vulnerable. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Authorization

Incorrect Privilege Assignment

Weakness Enumeration

Related Identifiers

CVE-2025-13118

Affected Products

Mall-Swarm