CVE-2025-13115: macrozheng mall-swarm/mall Order Details detail improper authorization
A security flaw has been discovered in macrozheng mall-swarm and mall up to 1.0.3. This impacts the function detail of the file /order/detail/ of the component Order Details Handler. Performing manipulation of the argument orderId results in improper authorization. It is possible to initiate the attack remotely. The exploit has been released to the public and may be exploited. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13115?
CVE-2025-13115 has been classified with a high severity due to improper authorization in the Order Details Handler.
How do I fix CVE-2025-13115?
To mitigate CVE-2025-13115, upgrade to a version of macrozheng mall-swarm that is higher than 1.0.3.
What components are affected by CVE-2025-13115?
CVE-2025-13115 affects the Order Details Handler function at the endpoint /order/detail/.
What type of vulnerability is CVE-2025-13115?
CVE-2025-13115 is an authorization vulnerability that allows manipulation of the orderId argument.
Who is the vendor for the affected software in CVE-2025-13115?
The affected software in CVE-2025-13115 belongs to the vendor macrozheng.