Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-12304

Опубликовано: 27 окт. 2025
Источник: nvd
CVSS3: 4.3
CVSS2: 4
EPSS Низкий

Описание

A vulnerability has been found in dulaiduwang003 TIME-SEA-PLUS up to fb299162f18498dd9cf17da906886d80a077d53b. This affects the function alipayIsSucceed of the file PayController.java of the component Order Status Handler. The manipulation leads to improper authorization. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.

EPSS

Процентиль: 11%
0.00037
Низкий

4.3 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-266

Связанные уязвимости

CVSS3: 4.3
github
3 месяца назад

A vulnerability has been found in dulaiduwang003 TIME-SEA-PLUS up to fb299162f18498dd9cf17da906886d80a077d53b. This affects the function alipayIsSucceed of the file PayController.java of the component Order Status Handler. The manipulation leads to improper authorization. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.

EPSS

Процентиль: 11%
0.00037
Низкий

4.3 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-266