CVE-2025-15085

Source
https://cve.org/CVERecord?id=CVE-2025-15085
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-15085.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-15085
Published
2025-12-25T19:32:08.203Z
Modified
2026-07-15T01:49:01.075417466Z
Severity
  • 2.1 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
youlaitech youlai-mall Balance MemberController.java deductBalance improper authorization
Details

A security flaw has been discovered in youlaitech youlai-mall 1.0.0/2.0.0. This affects the function deductBalance of the file mall-ums/ums-boot/src/main/java/com/youlai/mall/ums/controller/app/MemberController.java of the component Balance Handler. The manipulation results in improper authorization. The attack can be launched remotely. The exploit has been released to the public and may be exploited. The vendor was contacted early about this disclosure but did not respond in any way.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/15xxx/CVE-2025-15085.json",
    "cna_assigner": "VulDB",
    "unresolved_ranges": [
        {
            "source": "AFFECTED_FIELD",
            "extracted_events": [
                {
                    "introduced": "1.0.0"
                },
                {
                    "last_affected": "1.0.0"
                },
                {
                    "introduced": "2.0.0"
                },
                {
                    "last_affected": "2.0.0"
                }
            ]
        }
    ],
    "cwe_ids": [
        "CWE-266",
        "CWE-285"
    ]
}
References

Affected packages

Git / github.com/youlaitech/youlai-mall

Affected ranges

Type
GIT
Repo
https://github.com/youlaitech/youlai-mall
Events
Database specific
{
    "cpe": [
        "cpe:2.3:a:youlai:youlai-mall:1.0.0:*:*:*:*:*:*:*",
        "cpe:2.3:a:youlai:youlai-mall:2.0.0:*:*:*:*:*:*:*"
    ],
    "extracted_events": [
        {
            "introduced": "1.0.0"
        },
        {
            "last_affected": "1.0.0"
        },
        {
            "introduced": "2.0.0"
        },
        {
            "last_affected": "2.0.0"
        }
    ],
    "source": "CPE_STRING"
}

Affected versions

1.*
1.0.0
2.*
2.0.0
v1.*
v1.0.0
v2.*
v2.0
v2.0.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-15085.json"