macrozheng mall version 1.0.3 and prior contains an authentication vulnerability in the mall-portal password reset workflow that allows an unauthenticated attacker to reset arbitrary user account passwords using only a victim’s telephone number. The password reset flow exposes the one-time password (OTP) directly in the API response and validates password reset requests solely by comparing the provided OTP to a value stored by telephone number, without verifying user identity or ownership of the telephone number. This enables remote account takeover of any user with a known or guessable telephone number.
The password reset flow in the mall-portal component returns a one-time OTP code directly in the API response, disclosing it to the attacker. Verification of the password reset request is based solely on comparing the supplied OTP code with the value stored on the server associated with the phone number. The application does not verify the identity of the requester or actual ownership of the provided phone number. An attacker can therefore initiate a password reset for a victim, read the OTP from the API response, and set a new password for any account.
An attacker remotely takes full control of any user account for which they know or can guess the phone number. This results in unauthorized account access and loss of confidentiality and integrity of the victim's account data.
Patches available from the vendor should be applied according to the references. Temporarily, it is recommended to disable the password reset feature via phone number or implement a server-side phone number ownership verification mechanism (e.g., sending OTP only via SMS without including it in the API response) and introduce user identity validation in the password reset process.
Macrozheng Mall version 1.0.3 and earlier (mall-portal component).
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XMacrozheng Mall
APPMacrozheng≤ 1.0.3
Related vulnerabilities
A vulnerability has been found in macrozheng mall up to 1.0.3. This impacts an unknown function of the compone...
A vulnerability was found in macrozheng mall up to 1.0.3 and classified as problematic. This issue affects the...
A vulnerability was found in macrozheng mall 1.0.3. It has been rated as problematic. Affected by this issue i...
W macrozheng mall do wersji 1.0.3 wykryto lukę bezpieczeństwa dotyczącą nieznanego kodu w pliku /member/addres...
W mall macrozheng do wersji 1.0.3 wykryto podatność. Problem dotyczy funkcji delete w pliku /member/readHistor...