CVE-2025-13443

A vulnerability was detected in macrozheng mall up to 1.0.3. Affected by this issue is the function delete of the file /member/readHistory/delete. Performing manipulation of the argument ids results in improper access controls. Remote exploitation of the attack is possible. The exploit is now public and may be used.
References
Link Resource
https://github.com/Hwwg/cve/issues/15 Exploit Issue Tracking Third Party Advisory
https://vuldb.com/?ctiid.333016 Permissions Required VDB Entry
https://vuldb.com/?id.333016 Third Party Advisory VDB Entry
https://vuldb.com/?submit.690892 Third Party Advisory VDB Entry
https://github.com/Hwwg/cve/issues/15 Exploit Issue Tracking Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:macrozheng:mall:*:*:*:*:*:*:*:*

History

25 Nov 2025, 19:18

Type Values Removed Values Added
First Time Macrozheng
Macrozheng mall
CPE cpe:2.3:a:macrozheng:mall:*:*:*:*:*:*:*:*
References () https://github.com/Hwwg/cve/issues/15 - () https://github.com/Hwwg/cve/issues/15 - Exploit, Issue Tracking, Third Party Advisory
References () https://vuldb.com/?ctiid.333016 - () https://vuldb.com/?ctiid.333016 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.333016 - () https://vuldb.com/?id.333016 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.690892 - () https://vuldb.com/?submit.690892 - Third Party Advisory, VDB Entry

20 Nov 2025, 15:17

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-20 15:17

Updated : 2025-11-25 19:18


NVD link : CVE-2025-13443

Mitre link : CVE-2025-13443

CVE.ORG link : CVE-2025-13443


JSON object : View

Products Affected

macrozheng

  • mall
CWE
CWE-266

Incorrect Privilege Assignment

CWE-284

Improper Access Control