Metrics
Affected Vendors & Products
Fri, 05 Dec 2025 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Youlai
Youlai youlai-mall |
|
| Vendors & Products |
Youlai
Youlai youlai-mall |
Fri, 05 Dec 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 05 Dec 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability has been found in youlaitech youlai-mall 1.0.0/2.0.0. This impacts an unknown function of the file /app-api/v1/orders/. The manipulation of the argument orderId leads to improper control of dynamically-identified variables. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | youlaitech youlai-mall orders improper control of dynamically-identified variables | |
| Weaknesses | CWE-913 CWE-914 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2025-12-05T16:48:03.230Z
Reserved: 2025-12-05T08:35:03.860Z
Link: CVE-2025-14085
Updated: 2025-12-05T16:46:14.984Z
Status : Received
Published: 2025-12-05T14:15:48.633
Modified: 2025-12-05T14:15:48.633
Link: CVE-2025-14085
No data.