Sploitus

CVE-2025-9836

No indexed exploits for CVE-2025-9836 yet

A vulnerability was found in macrozheng mall up to 1.0.3. This vulnerability affects the function paySuccess of the file /order/paySuccess. The manipulation of the argument orderId results in authorization bypass. The attack can be launched remotely. The exploit has been made public and could be used.

Affected products
Macrozheng Mall
Macrozheng Mall
≤ 1.0.3
Fix
Available
CVSS 4.0
5.3 MEDIUM
CVSS 3.1
4.3 MEDIUM
EPSS
0.3% (21th percentile)
Weakness
CWE-285, CWE-639
NVD status
Analyzed
Published
2025-09-02
CVE-2025-9836 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2025-9836 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2025-9836 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.