CVE-2025-28399
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Apr 15, 2025
Updated: Apr 25, 2025
CWE ID 269
Summary
CVE-2025-28399 is a privilege escalation vulnerability affecting Erick xmall version 1.1 and earlier. An attacker can exploit this issue by manipulating the updateAddress method of the Address Controller class, which allows for escalated privileges to be gained remotely. This vulnerability poses a serious risk for impacted systems and requires immediate attention from administrators to apply the necessary patch or workaround to prevent potential unauthorized access and privilege escalation.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.