Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 07 Jan 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:macrozheng:mall:*:*:*:*:*:*:*:* |
Mon, 29 Dec 2025 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Macrozheng
Macrozheng mall |
|
| Vendors & Products |
Macrozheng
Macrozheng mall |
Mon, 29 Dec 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 28 Dec 2025 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security vulnerability has been detected in macrozheng mall up to 1.0.3. This vulnerability affects unknown code of the file /member/address/update/ of the component Member Endpoint. The manipulation leads to improper authorization. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. | |
| Title | macrozheng mall Member Endpoint update improper authorization | |
| Weaknesses | CWE-266 CWE-285 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2025-12-29T16:40:10.112Z
Reserved: 2025-12-27T08:48:43.979Z
Link: CVE-2025-15118
Updated: 2025-12-29T16:40:04.515Z
Status : Analyzed
Published: 2025-12-28T04:16:03.413
Modified: 2026-04-29T01:00:01.613
Link: CVE-2025-15118
No data.
OpenCVE Enrichment
Updated: 2025-12-29T22:33:14Z