Junglewise Threat Intelligence

CVE-2025-13118: macrozheng mall improper authorization in paySuccess function

CVE-2025-13118 · Severity: medium · CVSS 6.3 · Published 2025-11-13

Technologies: Macrozheng Mall. Vendors: Macrozheng.

Executive brief

A security flaw exists in the macrozheng mall and mall-swarm e-commerce platforms, which are used to manage online shopping and order processing. An attacker can exploit this vulnerability to manipulate payment status for orders belonging to other customers. This could lead to financial discrepancies, unauthorized order fulfillment, and a loss of customer trust.

Technical details

An Insecure Direct Object Reference (IDOR) vulnerability exists in the /order/paySuccess endpoint of the macrozheng mall and mall-swarm applications. The application accepts an orderID parameter via a POST request but fails to verify if the order belongs to the authenticated user making the request. A remote attacker with a valid account can manipulate the orderID argument to trigger a successful payment status for any order in the system. This vulnerability is public, and as of the advisory date, the vendor has not responded to disclosure attempts.

Affected products

  • macrozheng mall-swarm up to 1.0.3
  • macrozheng mall up to 1.0.3

Timeline

  • 2025-10-27: disclosed: Initial disclosure for mall-swarm on GitHub
  • 2025-10-31: disclosed: Disclosure for mall on GitHub
  • 2025-11-13: advisory: NVD publication date

References

Related threats