CVE-2025-28399

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Apr 15, 2025
Updated: Apr 25, 2025
CWE ID 269

Summary

CVE-2025-28399 is a privilege escalation vulnerability affecting Erick xmall version 1.1 and earlier. An attacker can exploit this issue by manipulating the updateAddress method of the Address Controller class, which allows for escalated privileges to be gained remotely. This vulnerability poses a serious risk for impacted systems and requires immediate attention from administrators to apply the necessary patch or workaround to prevent potential unauthorized access and privilege escalation.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share