CVE-2025-13443

Source
https://cve.org/CVERecord?id=CVE-2025-13443
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-13443.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-13443
Published
2025-11-20T15:17:25.267Z
Modified
2026-03-14T12:41:29.743007Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

A vulnerability was detected in macrozheng mall up to 1.0.3. Affected by this issue is the function delete of the file /member/readHistory/delete. Performing manipulation of the argument ids results in improper access controls. Remote exploitation of the attack is possible. The exploit is now public and may be used.

References

Affected packages

Git /

Affected ranges

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-13443.json"
unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "1.0.3"
            }
        ]
    }
]