Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qwp5-2j5x-f2qf

Опубликовано: 20 нояб. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 2.1
CVSS3: 5.4

Описание

A vulnerability was detected in macrozheng mall up to 1.0.3. Affected by this issue is the function delete of the file /member/readHistory/delete. Performing manipulation of the argument ids results in improper access controls. Remote exploitation of the attack is possible. The exploit is now public and may be used.

A vulnerability was detected in macrozheng mall up to 1.0.3. Affected by this issue is the function delete of the file /member/readHistory/delete. Performing manipulation of the argument ids results in improper access controls. Remote exploitation of the attack is possible. The exploit is now public and may be used.

EPSS

Процентиль: 11%
0.00036
Низкий

2.1 Low

CVSS4

5.4 Medium

CVSS3

Дефекты

CWE-266

Связанные уязвимости

CVSS3: 5.4
nvd
3 месяца назад

A vulnerability was detected in macrozheng mall up to 1.0.3. Affected by this issue is the function delete of the file /member/readHistory/delete. Performing manipulation of the argument ids results in improper access controls. Remote exploitation of the attack is possible. The exploit is now public and may be used.

EPSS

Процентиль: 11%
0.00036
Низкий

2.1 Low

CVSS4

5.4 Medium

CVSS3

Дефекты

CWE-266