VulnerabilityAnalyzed
CVE-2025-9514
A vulnerability has been found in macrozheng mall up to 1.0.3.
MEDIUM 6.3EPSS 0.39%
Does this matter?
Lower severity and a low EPSS score (0.39%). Track it; it rarely justifies an emergency change on its own.
Description
A vulnerability has been found in macrozheng mall up to 1.0.3. This impacts an unknown function of the component Registration. Such manipulation leads to weak password requirements. The attack can be executed remotely. Attacks of this nature are highly complex. The exploitability is said to be difficult. The vendor deleted the GitHub issue for this vulnerability without and explanation.
- CVSS 4.0
- 6.3 MEDIUMCVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.39% probability · 33th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-521
- Affected
- macrozheng/mall
- Source
- cna@vuldb.com
References
- https://github.com/macrozheng/mall/issues/923Not Applicable
- https://vuldb.com/?ctiid.321507Permissions Required, VDB Entry
- https://vuldb.com/?id.321507Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.635503Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.