CVE-2025-13443

Source
https://nvd.nist.gov/vuln/detail/CVE-2025-13443
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-13443.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-13443
Published
2025-11-20T15:17:25.267Z
Modified
2025-12-02T20:30:51.265498Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

A vulnerability was detected in macrozheng mall up to 1.0.3. Affected by this issue is the function delete of the file /member/readHistory/delete. Performing manipulation of the argument ids results in improper access controls. Remote exploitation of the attack is possible. The exploit is now public and may be used.

References

Affected packages

Git / github.com/macrozheng/mall

Affected ranges

Type
GIT
Repo
https://github.com/macrozheng/mall
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected

Affected versions

v1.*

v1.0.0
v1.0.1
v1.0.2
v1.0.3