CVE-2025-14016

A security vulnerability has been detected in macrozheng mall-swarm up to 1.0.3. Affected is the function delete of the file /member/readHistory/delete. Such manipulation of the argument ids leads to improper authorization. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
References
Link Resource
https://github.com/Hwwg/cve/issues/17 Exploit Third Party Advisory Issue Tracking
https://vuldb.com/?ctiid.334257 Permissions Required VDB Entry
https://vuldb.com/?id.334257 Third Party Advisory VDB Entry
https://vuldb.com/?submit.694797 Third Party Advisory VDB Entry
https://github.com/Hwwg/cve/issues/17 Exploit Third Party Advisory Issue Tracking
Configurations

Configuration 1 (hide)

cpe:2.3:a:macrozheng:mall-swarm:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-12-04 19:16

Updated : 2025-12-15 15:44


NVD link : CVE-2025-14016

Mitre link : CVE-2025-14016

CVE.ORG link : CVE-2025-14016


JSON object : View

Products Affected

macrozheng

  • mall-swarm
CWE
CWE-266

Incorrect Privilege Assignment

CWE-285

Improper Authorization

CWE-863

Incorrect Authorization