CVE-2025-13443: macrozheng mall delete access control
A vulnerability was detected in macrozheng mall up to 1.0.3. Affected by this issue is the function delete of the file /member/readHistory/delete. Performing manipulation of the argument ids results in improper access controls. Remote exploitation of the attack is possible. The exploit is now public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13443?
CVE-2025-13443 is classified as a critical vulnerability due to its potential for remote exploitation.
How do I fix CVE-2025-13443?
To fix CVE-2025-13443, update the macrozheng mall software to version 1.0.4 or later where the vulnerability has been addressed.
What systems are affected by CVE-2025-13443?
CVE-2025-13443 affects macrozheng mall versions up to and including 1.0.3.
What kind of attack does CVE-2025-13443 enable?
CVE-2025-13443 enables attackers to perform unauthorized access and manipulation of user read history.
Is remote exploitation possible with CVE-2025-13443?
Yes, CVE-2025-13443 allows for remote exploitation due to improper access controls.