Impact
A flaw in macrozheng mall 0504e86, located in the /sso/getAuthCode endpoint of the mall-portal module, permits an attacker to manipulate the password recovery process, resulting in a weak authentication reset that could enable unauthorized account access. The vulnerability is based on CWE-640 and directly compromises the integrity of the password reset mechanism.
Affected Systems
Victims of this flaw run the macrozheng mall application, specifically the 0504e86 revision of the mall-portal module. No other versions are listed as affected in the available data, but any deployment using this codebase may be susceptible.
Risk and Exploitability
The CVSS score of 6.3 classifies the issue as medium severity. Although no EPSS score is published, the vulnerability can be exploited remotely and is reported to have a high complexity yet is considered difficult to exploit. The exploit code has been publicly disclosed, and the vulnerability is not currently catalogued in the CISA KEV list.
OpenCVE Enrichment