ZeroHour

Vulnerabilities

10 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-36331
Incorrect access control in the /member/orderList API of xmall v1.1 allows attackers to arbitrarily access other users' order details via manipulation of the qu

Incorrect access control in the /member/orderList API of xmall v1.1 allows attackers to arbitrarily access other users' order details via manipulation of the query parameter userId.

NVD description · AI analysis pending
8.2<1% PoC
  • exrick xmall
CVE-2025-65540
Multiple Cross-Site Scripting (XSS) vulnerabilities exist in xmall v1.1 due to improper handling of user-supplied data.

Multiple Cross-Site Scripting (XSS) vulnerabilities exist in xmall v1.1 due to improper handling of user-supplied data. User input fields such as username and description are directly rendered into HTML without proper sanitization or encoding, allowing attackers to inject and execute malicious scripts.

NVD description · AI analysis pending
6.1<1% PoC
  • exrick xmall
CVE-2025-8525
+3 in the same advisory: …8528 …8526 …8527
A vulnerability was found in Exrick xboot up to 3.3.4.

A vulnerability was found in Exrick xboot up to 3.3.4. It has been classified as problematic. This affects an unknown part of the component Spring Boot Admin/Spring Actuator. The manipulation leads to information disclosure. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

NVD description · AI analysis pending
5.5
group max
<1% PoC ×2
  • exrick xboot
CVE-2025-45612
Incorrect access control in xmall v1.1 allows attackers to bypass authentication via a crafted GET request to /index.

Incorrect access control in xmall v1.1 allows attackers to bypass authentication via a crafted GET request to /index.

NVD description · AI analysis pending
9.8<1% PoC
  • exrick xmall
CVE-2025-28399
An issue in Erick xmall v.1.1 and before allows a remote attacker to escalate privileges via the updateAddress method of the Address Controller class.

An issue in Erick xmall v.1.1 and before allows a remote attacker to escalate privileges via the updateAddress method of the Address Controller class.

NVD description · AI analysis pending
9.8<1% PoC
  • exrick xmall
CVE-2024-24112
xmall v1.1 was discovered to contain a SQL injection vulnerability via the orderDir parameter.

xmall v1.1 was discovered to contain a SQL injection vulnerability via the orderDir parameter.

NVD description · AI analysis pending
9.83% PoC
  • exrick xmall
CVE-2021-43432
A Cross Site Scripting (XSS) vulnerability exists in Exrick XMall Admin Panel as of 11/7/2021 via the GET parameter in product-add.jsp.

A Cross Site Scripting (XSS) vulnerability exists in Exrick XMall Admin Panel as of 11/7/2021 via the GET parameter in product-add.jsp.

NVD description · AI analysis pending
6.1<1%
  • exrick xmall