CVE-2025-9514
BaseFortify
Publication date: 2025-08-27
Last updated on: 2025-11-26
Assigner: VulDB
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| macrozheng | mall | to 1.0.3 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-521 | The product does not require that users should have strong passwords. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability exists in macrozheng mall up to version 1.0.3, specifically in the Registration component. It allows manipulation that leads to weak password requirements. The attack can be executed remotely but is highly complex and difficult to exploit. The vendor removed the related GitHub issue without explanation.
How can this vulnerability impact me? :
The vulnerability can lead to weak password enforcement during user registration, potentially allowing attackers to create accounts with weak passwords. This could increase the risk of unauthorized access if attackers exploit weak credentials. However, the attack is complex and difficult to execute remotely.