CVE-2025-14085CWE-913CWE-914

youlaitech youlai-mall orders improper control of dynamically-identified variables

Medium · published December 5, 2025

CVSS v4.0
5.3
EPSS
0%
Percentile
33.4
In the wild
Unconfirmed
What it is

A vulnerability has been found in youlaitech youlai-mall 1.0.0/2.0.0. This impacts an unknown function of the file /app-api/v1/orders/. The manipulation of the argument orderId leads to improper control of dynamically-identified variables. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

The record
Technical detail
CVSS v4.0
5.3 · MEDIUM
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
EPSS
0.00401 · 33.4th percentile
Weaknesses
CWE-913 · Improper Control of Dynamically-Managed Code Resources; CWE-914 · Improper Control of Dynamically-Identified Variables
Published
2025-12-05T14:02Z
EPSS history
Timeline
  • 05 DEC 14:02Z
    youlaitech youlai-mall orders improper control of dynamically-identified variables
    cvelistv5