CVE-2025-13116: macrozheng mall-swarm/mall cancelUserOrder improper authorization
A weakness has been identified in macrozheng mall-swarm and mall up to 1.0.3. Affected is the function cancelUserOrder of the file /order/cancelUserOrder. Executing manipulation of the argument orderId can lead to improper authorization. It is possible to launch the attack remotely. The exploit has been made available to the public and could be exploited. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13116?
CVE-2025-13116 is classified as a security vulnerability that can potentially lead to improper authorization.
How do I fix CVE-2025-13116?
To mitigate CVE-2025-13116, update the macrozheng mall-swarm software to a version later than 1.0.3.
What are the potential impacts of CVE-2025-13116?
The impact of CVE-2025-13116 may include unauthorized access to user orders and data manipulation.
Who is affected by CVE-2025-13116?
CVE-2025-13116 affects users of macrozheng mall-swarm versions up to and including 1.0.3.
Can CVE-2025-13116 be exploited remotely?
Yes, CVE-2025-13116 can be exploited remotely through manipulation of the orderId argument.