CRITICAL🇵🇱 Wersja polska

CVE-2026-25858

CVSS 9.3v4.0pub. 2026-02-07upd. 2026-04-07

macrozheng mall version 1.0.3 and prior contains an authentication vulnerability in the mall-portal password reset workflow that allows an unauthenticated attacker to reset arbitrary user account passwords using only a victim’s telephone number. The password reset flow exposes the one-time password (OTP) directly in the API response and validates password reset requests solely by comparing the provided OTP to a value stored by telephone number, without verifying user identity or ownership of the telephone number. This enables remote account takeover of any user with a known or guessable telephone number.

🤖 AI Analysis
How it works

The password reset flow in the mall-portal component returns a one-time OTP code directly in the API response, disclosing it to the attacker. Verification of the password reset request is based solely on comparing the supplied OTP code with the value stored on the server associated with the phone number. The application does not verify the identity of the requester or actual ownership of the provided phone number. An attacker can therefore initiate a password reset for a victim, read the OTP from the API response, and set a new password for any account.

Impact

An attacker remotely takes full control of any user account for which they know or can guess the phone number. This results in unauthorized account access and loss of confidentiality and integrity of the victim's account data.

Mitigation & patch

Patches available from the vendor should be applied according to the references. Temporarily, it is recommended to disable the password reset feature via phone number or implement a server-side phone number ownership verification mechanism (e.g., sending OTP only via SMS without including it in the API response) and introduce user identity validation in the password reset process.

Who is affected

Macrozheng Mall version 1.0.3 and earlier (mall-portal component).

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Macrozheng Mall

    APP
    Macrozheng
    ≤ 1.0.3
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2025-9514MEDIUM6.3same product

A vulnerability has been found in macrozheng mall up to 1.0.3. This impacts an unknown function of the compone...

CVE-2025-8755MEDIUM5.5same product

A vulnerability was found in macrozheng mall up to 1.0.3 and classified as problematic. This issue affects the...

CVE-2025-8742MEDIUM6.3same product

A vulnerability was found in macrozheng mall 1.0.3. It has been rated as problematic. Affected by this issue i...

CVE-2025-15118LOW2.1same product

W macrozheng mall do wersji 1.0.3 wykryto lukę bezpieczeństwa dotyczącą nieznanego kodu w pliku /member/addres...

CVE-2025-13443LOW2.1same product

W mall macrozheng do wersji 1.0.3 wykryto podatność. Problem dotyczy funkcji delete w pliku /member/readHistor...