A vulnerability has been found in macrozheng mall up to 1.0.3. This affects the function cancelOrder of the file /order/cancelUserOrder. The manipulation of the argument orderId leads to authorization bypass. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Metrics
Affected Vendors & Products
References
History
Tue, 02 Sep 2025 21:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability has been found in macrozheng mall up to 1.0.3. This affects the function cancelOrder of the file /order/cancelUserOrder. The manipulation of the argument orderId leads to authorization bypass. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. | |
Title | macrozheng mall cancelUserOrder cancelOrder authorization | |
Weaknesses | CWE-285 CWE-639 |
|
References |
| |
Metrics |
cvssV2_0
|

Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2025-09-02T21:32:06.106Z
Reserved: 2025-09-02T12:49:10.110Z
Link: CVE-2025-9835

No data.

Status : Received
Published: 2025-09-02T22:15:33.007
Modified: 2025-09-02T22:15:33.007
Link: CVE-2025-9835

No data.

No data.