CVE-2025-14016

A security vulnerability has been detected in macrozheng mall-swarm up to 1.0.3. Affected is the function delete of the file /member/readHistory/delete. Such manipulation of the argument ids leads to improper authorization. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
References
Link Resource
https://github.com/Hwwg/cve/issues/17 Exploit Third Party Advisory Issue Tracking
https://vuldb.com/?ctiid.334257 Permissions Required VDB Entry
https://vuldb.com/?id.334257 Third Party Advisory VDB Entry
https://vuldb.com/?submit.694797 Third Party Advisory VDB Entry
https://github.com/Hwwg/cve/issues/17 Exploit Third Party Advisory Issue Tracking
Configurations

Configuration 1 (hide)

cpe:2.3:a:macrozheng:mall-swarm:*:*:*:*:*:*:*:*

History

15 Dec 2025, 15:44

Type Values Removed Values Added
First Time Macrozheng mall-swarm
Macrozheng
CWE CWE-863
CPE cpe:2.3:a:macrozheng:mall-swarm:*:*:*:*:*:*:*:*
References () https://github.com/Hwwg/cve/issues/17 - () https://github.com/Hwwg/cve/issues/17 - Exploit, Third Party Advisory, Issue Tracking
References () https://vuldb.com/?ctiid.334257 - () https://vuldb.com/?ctiid.334257 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.334257 - () https://vuldb.com/?id.334257 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.694797 - () https://vuldb.com/?submit.694797 - Third Party Advisory, VDB Entry

05 Dec 2025, 20:15

Type Values Removed Values Added
References () https://github.com/Hwwg/cve/issues/17 - () https://github.com/Hwwg/cve/issues/17 -

04 Dec 2025, 19:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-04 19:16

Updated : 2025-12-15 15:44


NVD link : CVE-2025-14016

Mitre link : CVE-2025-14016

CVE.ORG link : CVE-2025-14016


JSON object : View

Products Affected

macrozheng

  • mall-swarm
CWE
CWE-266

Incorrect Privilege Assignment

CWE-285

Improper Authorization

CWE-863

Incorrect Authorization