CVE-2025-14051
A flaw has been found in youlaitech youlai-mall 1.0.0/2.0.0. Affected is the function getById/updateAddress/deleteAddress of the file /mall-ums/app-api/v1/addresses/. Executing manipulation can lead to improper control of dynamically-identified variables. The attack can be executed remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.5
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
- EPSS probability
- 0.47%
- CWE
- CWE-914, CWE-913
- Published
- 2025-12-04
- Last modified
- 2026-03-12
Affected products
- youlaitech youlai-mall
- youlaitech youlai-mall
Weakness type
Related vulnerabilities
- CVE-2026-35173 — Chyrp Lite has an IDOR via Mass Assignment in Post Model
- CVE-2025-14085 — youlaitech youlai-mall orders improper control of dynamically-identified variables
- CVE-2024-54198 — Information Disclosure vulnerability through Remote Function Call (RFC) in SAP NetWeaver Application Server ABAP
- CVE-2024-24914 — Authenticated Gaia users can inject code or commands by global variables through special HTTP...
- CVE-2023-33175 — ToUI allows user-specific variables to be shared between users