CVE-2025-10422 | newbee-mall up to 613a662adf1da7623ec34459bc83e3c1b12d8ce7 Order Status /paySuccess orderNo improper authorization (Issue 100 / EUVD-2025-29147)
A vulnerability was found in newbee-mall up to 613a662adf1da7623ec34459bc83e3c1b12d8ce7. It has been rated as critical. This issue affects the function paySuccess of the file /paySuccess of the component Order Status Handler. The manipulation of the argument orderNo leads to improper authorization.
This vulnerability is referenced as CVE-2025-10422. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided.