Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-22176 | A vulnerability was found in jerryshensjf JPACookieShop 蛋糕商城JPA版 1.0 and classified as critical. This issue affects the function updateGoods of the file GoodsController.java. The manipulation leads to authorization bypass. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 06 Nov 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jerryshensjf
Jerryshensjf jpacookieshop |
|
| CPEs | cpe:2.3:a:jerryshensjf:jpacookieshop:-:*:*:*:*:*:*:* | |
| Vendors & Products |
Jerryshensjf
Jerryshensjf jpacookieshop |
Tue, 22 Jul 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 21 Jul 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was found in jerryshensjf JPACookieShop 蛋糕商城JPA版 1.0 and classified as critical. This issue affects the function updateGoods of the file GoodsController.java. The manipulation leads to authorization bypass. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. | |
| Title | jerryshensjf JPACookieShop 蛋糕商城JPA版 GoodsController.java updateGoods authorization | |
| Weaknesses | CWE-285 CWE-639 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2025-07-22T16:04:37.544Z
Reserved: 2025-07-21T07:13:44.028Z
Link: CVE-2025-7938
Updated: 2025-07-22T16:04:34.401Z
Status : Analyzed
Published: 2025-07-21T20:15:56.803
Modified: 2025-11-06T16:12:01.390
Link: CVE-2025-7938
No data.
OpenCVE Enrichment
No data.
EUVD