Executive brief
A security flaw in the macrozheng mall e-commerce platform allows anyone to take over user accounts if they know the user's phone number. The system's password reset process accidentally reveals the secret security code (OTP) in the background web traffic, which an attacker can use to change a victim's password. This could lead to unauthorized access to customer accounts, personal data theft, and disruption of store operations.
Technical details
An authentication bypass vulnerability exists in the mall-portal component of macrozheng mall due to a weak password recovery mechanism (CWE-640). The password reset workflow leaks the generated One-Time Password (OTP) directly within the API response to the client. Furthermore, the application validates reset requests by comparing the provided OTP against a value indexed only by the telephone number, without verifying the requester's identity or session. A remote, unauthenticated attacker can exploit this by requesting a reset for a known phone number, capturing the leaked OTP from the response, and successfully resetting the account password to gain full control.
Affected products
- macrozheng mall <= 1.0.3
Timeline
- 2026-02-07: advisory: Initial advisory published by VulnCheck
- 2026-02-07: disclosed: CVE-2026-25858 assigned