CVE-2025-15496

critical
Published 2026-01-09 · Modified 2026-04-29
CVSS v3
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2
6.5
VIR risk
9.8

Description

A vulnerability was determined in guchengwuyue yshopmall up to 1.9.1. Affected is the function getPage of the file /api/jobs. This manipulation of the argument sort causes sql injection. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.

Predictions

Exploit likelihood
97%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: cna@vuldb.com — https://github.com/guchengwuyue/yshopmall/issues/39#issue-3769727898

vendor Authored 2026-05-27

Vendor advisory: cna@vuldb.com — https://github.com/guchengwuyue/yshopmall/issues/39

Application impact

VendorProductVersionsFixed
guchengwuyueyshopmall{"endIncluding":"1.9.1"}

References

CWEs

CWE-74 CWE-89

Verify integrity in audit chain (admin only). AS-IS.