Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 30 Oct 2025 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Yiovo
Yiovo firefly Mall |
|
| CPEs | cpe:2.3:a:yiovo:firefly_mall:*:*:*:*:open_source:*:*:* | |
| Vendors & Products |
Xany
Xany yoshop2.0 |
Yiovo
Yiovo firefly Mall |
Tue, 07 Oct 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Xany
Xany yoshop2.0 |
|
| CPEs | cpe:2.3:a:xany:yoshop2.0:-:*:*:*:*:*:*:* | |
| Vendors & Products |
Xany
Xany yoshop2.0 |
Fri, 03 Oct 2025 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Yoshop
Yoshop yoshop |
|
| Vendors & Products |
Yoshop
Yoshop yoshop |
Thu, 02 Oct 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-200 | |
| Metrics |
cvssV3_1
|
Thu, 02 Oct 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | YOSHOP 2.0 allows unauthenticated information disclosure via comment-list API endpoints in the Goods module. The Comment model eagerly loads the related User model without field filtering; because User.php defines no $hidden or $visible attributes, sensitive fields (bcrypt password hash, mobile number, pay_money, expend_money.) are exposed in JSON responses. Route names vary per deployment (e.g. /api/goods.pinglun/list), but all call the same vulnerable model logic. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-10-02T18:13:36.507Z
Reserved: 2025-08-16T00:00:00.000Z
Link: CVE-2025-56161
Updated: 2025-10-02T18:13:30.669Z
Status : Analyzed
Published: 2025-10-02T16:15:34.910
Modified: 2025-10-30T18:33:14.820
Link: CVE-2025-56161
No data.
OpenCVE Enrichment
Updated: 2025-10-03T08:22:44Z