CVE-2025-14052

Source
https://cve.org/CVERecord?id=CVE-2025-14052
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-14052.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-14052
Published
2025-12-05T00:02:06.424Z
Modified
2026-07-15T01:49:11.323594678Z
Severity
  • 2.1 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
youlaitech youlai-mall members getMemberById access control
Details

A vulnerability has been found in youlaitech youlai-mall 1.0.0/2.0.0. Affected by this vulnerability is the function getMemberById of the file /mall-ums/app-api/v1/members/. The manipulation of the argument memberId leads to improper access controls. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/14xxx/CVE-2025-14052.json",
    "unresolved_ranges": [
        {
            "source": "AFFECTED_FIELD",
            "extracted_events": [
                {
                    "introduced": "1.0.0"
                },
                {
                    "last_affected": "1.0.0"
                },
                {
                    "introduced": "2.0.0"
                },
                {
                    "last_affected": "2.0.0"
                }
            ]
        }
    ],
    "cna_assigner": "VulDB",
    "cwe_ids": [
        "CWE-266",
        "CWE-284"
    ]
}
References

Affected packages

Git / github.com/youlaitech/youlai-mall

Affected ranges

Type
GIT
Repo
https://github.com/youlaitech/youlai-mall
Events
Database specific
{
    "source": "CPE_STRING",
    "extracted_events": [
        {
            "introduced": "1.0.0"
        },
        {
            "last_affected": "1.0.0"
        },
        {
            "introduced": "2.0.0"
        },
        {
            "last_affected": "2.0.0"
        }
    ],
    "cpe": [
        "cpe:2.3:a:youlai:youlai-mall:1.0.0:*:*:*:*:*:*:*",
        "cpe:2.3:a:youlai:youlai-mall:2.0.0:*:*:*:*:*:*:*"
    ]
}

Affected versions

1.*
1.0.0
2.*
2.0.0
v1.*
v1.0.0
v2.*
v2.0
v2.0.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-14052.json"