PT-2025-53414 · Youlaitech · Youlai-Mall

Huangweigang

+1

·

Published

2025-12-25

·

Updated

2026-02-26

·

CVE-2025-15087

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions youlaitech youlai-mall versions 1.0.0 through 2.0.0
Description A security issue has been identified in youlaitech youlai-mall. Manipulation of the orderSn argument within the submitOrderPayment function, located in the file mall-oms/oms-boot/src/main/java/com/youlai/mall/oms/controller/app/OrderController.java, can lead to improper authorization. This issue may be exploited remotely. The exploit for this issue has been publicly disclosed. The existence of this issue is currently questioned, and the vendor has not responded to reports about it.
Recommendations youlaitech youlai-mall versions 1.0.0 through 2.0.0: Address improper authorization by securing the submitOrderPayment function and validating the orderSn argument.

Exploit

Fix

Improper Authorization

Incorrect Privilege Assignment

Weakness Enumeration

Related Identifiers

CVE-2025-15087

Affected Products

Youlai-Mall