CVE-2025-14085
A vulnerability has been found in youlaitech youlai-mall 1.0.0/2.0.0. This impacts an unknown function of the file /app-api/v1/orders/. The manipulation of the argument orderId leads to improper control of dynamically-identified variables. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.5
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
- EPSS probability
- 0.40%
- CWE
- CWE-914, CWE-913
- Published
- 2025-12-05
- Last modified
- 2026-03-12
Affected products
- youlaitech youlai-mall
- youlaitech youlai-mall
Weakness type
Related vulnerabilities
- CVE-2026-35173 — Chyrp Lite has an IDOR via Mass Assignment in Post Model
- CVE-2025-14051 — youlaitech youlai-mall addresses deleteAddress improper control of dynamically-identified variables
- CVE-2024-54198 — Information Disclosure vulnerability through Remote Function Call (RFC) in SAP NetWeaver Application Server ABAP
- CVE-2024-24914 — Authenticated Gaia users can inject code or commands by global variables through special HTTP...
- CVE-2023-33175 — ToUI allows user-specific variables to be shared between users