PT-2025-53413 · Youlaitech · Youlai-Mall

Huangweigang

·

Published

2025-12-25

·

Updated

2025-12-31

·

CVE-2025-15086

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions youlaitech youlai-mall versions 1.0.0 through 2.0.0
Description A weakness exists that causes improper access controls. The issue impacts the getMemberByMobile function within the file mall-ums/ums-boot/src/main/java/com/youlai/mall/ums/controller/app/MemberController.java. The attack can be initiated remotely, and the exploit is publicly available. The vendor was contacted regarding this disclosure but did not respond.
Recommendations youlaitech youlai-mall version 1.0.0: At the moment, there is no information about a newer version that contains a fix for this vulnerability. youlaitech youlai-mall version 2.0.0: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Access Control

Incorrect Privilege Assignment

Weakness Enumeration

Related Identifiers

CVE-2025-15086

Affected Products

Youlai-Mall