Improper Authorization in newbee-mall Order Status Functionality
CVE-2025-10422
Key Information:
- Vendor
newbee-ltd
- Status
- Vendor
- CVE Published:
- 15 September 2025
Badges
What is CVE-2025-10422?
An improper authorization vulnerability exists in the order status handler functionality of newbee-mall. Specifically, the 'paySuccess' method is susceptible to manipulation through the 'orderNo' argument. This vulnerability could allow an attacker to exploit the system remotely, gaining unauthorized access to sensitive order information. The issue has been made public, raising concerns about potential exploitation. As newbee-mall operates via a rolling release strategy, specific version details for affected or patched releases are not available.
Affected Version(s)
newbee-mall 613a662adf1da7623ec34459bc83e3c1b12d8ce7
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved