PT-2025-48185 · Unknown · Grocerymart

Published

2025-11-26

·

Updated

2025-12-30

·

CVE-2025-65278

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions GroceryMart versions prior to commit 21934e6 (2020-10-23)
Description An issue exists in the users.json file that allows unauthenticated attackers to obtain sensitive information, including plaintext usernames and passwords. The affected commit is 21934e6 from 2020-10-23.
Recommendations Update to a version later than or equal to commit 21934e6 (2020-10-23).

Exploit

Fix

Information Disclosure

Cleartext Storage of Sensitive Information

Weakness Enumeration

Related Identifiers

CVE-2025-65278

Affected Products

Grocerymart