CVE-2025-8755 | macrozheng mall up to 1.0.3 com.macro.mall.portal.controller UmsMemberController.java detail orderId authorization (EUVD-2025-24050)
A vulnerability was found in macrozheng mall up to 1.0.3 and classified as problematic. This issue affects the function detail of the file UmsMemberController.java of the component com.macro.mall.portal.controller. The manipulation of the argument orderId leads to authorization bypass.
The identification of this vulnerability is CVE-2025-8755. The attack may be initiated remotely. Furthermore, there is an exploit available.
It is recommended to apply restrictive firewalling.
The vendor was contacted early about this disclosure but did not respond in any way.