Improper Access Control in Youlaitech Youlai-Mall Affects Member Functionality
CVE-2025-15086
Key Information:
- Vendor
Youlaitech
- Status
- Vendor
- CVE Published:
- 25 December 2025
Badges
What is CVE-2025-15086?
A security weakness has been identified in Youlaitech's Youlai-Mall versions 1.0.0 and 2.0.0. This vulnerability impacts the getMemberByMobile function located in the MemberController.java file, allowing for improper access control. The vulnerability can be exploited remotely, putting users' sensitive information at risk. This issue has been publicly disclosed, and potential attackers may leverage the exploit. Despite being contacted about this vulnerability, the vendor has not responded to address the concern.
Affected Version(s)
youlai-mall 1.0.0
youlai-mall 2.0.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
