CVE-2025-9835: macrozheng mall cancelUserOrder cancelOrder authorization
A vulnerability has been found in macrozheng mall up to 1.0.3. This affects the function cancelOrder of the file /order/cancelUserOrder. The manipulation of the argument orderId leads to authorization bypass. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9835?
CVE-2025-9835 is considered a high severity vulnerability due to its potential for unauthorized access.
How do I fix CVE-2025-9835?
To fix CVE-2025-9835, update the macrozheng mall to version 1.0.4 or later, which contains necessary security patches.
What systems are affected by CVE-2025-9835?
CVE-2025-9835 affects macrozheng mall versions up to and including 1.0.3.
What type of attack is associated with CVE-2025-9835?
CVE-2025-9835 is associated with remote exploitation that allows for authorization bypass through the cancelOrder function.
Is there a known exploit for CVE-2025-9835?
Yes, there is a known exploit for CVE-2025-9835, which has been publicly disclosed, allowing attackers to leverage the vulnerability.