CVE-2025-13443 is an improper access control vulnerability affecting macrozheng mall up to version 1.0.3, specifically within the /member/readHistory/delete function. By manipulating the 'ids' argument, an unauthenticated attacker can achieve remote exploitation, leading to potential unauthorized access to sensitive information (C:L) and data modification (I:L). With a CVSS score of 6.5 (Medium), this vulnerability has publicly available exploit code, though it currently shows minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.0.3CPE matchmatch criteria | cpe:2.3:a:macrozheng:mall:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.