CVE-2025-13114: macrozheng mall-swarm attr updateAttr improper authorization
A vulnerability was identified in macrozheng mall-swarm up to 1.0.3. This affects the function updateAttr of the file /cart/update/attr. Such manipulation leads to improper authorization. The attack may be performed from remote. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13114?
CVE-2025-13114 has a high severity due to its potential for unauthorized access and exploitation.
How do I fix CVE-2025-13114?
To fix CVE-2025-13114, update the macrozheng mall-swarm software to version 1.0.4 or later.
What affects CVE-2025-13114?
CVE-2025-13114 affects macrozheng mall-swarm versions up to 1.0.3.
Can CVE-2025-13114 be exploited remotely?
Yes, CVE-2025-13114 can be exploited remotely, allowing unauthorized actions from a distance.
What specific function is vulnerable in CVE-2025-13114?
The vulnerable function in CVE-2025-13114 is updateAttr located in the /cart/update/attr file.