9.8
CVSSv3

CVE-2025-28399

CVSSv4: NA | CVSSv3: 9.8 | CVSSv2: NA | VMScore: 1000 | EPSS: 0.00172 | KEV: Not Included
Published: 15/04/2025 Updated: 25/04/2025

Vulnerability Summary

Privilege Escalation in Erick xmall v1.1 via Address Controller Method

An issue in Erick xmall v.1.1 and before allows a remote malicious user to escalate privileges via the updateAddress method of the Address Controller class.

Vulnerable Product Search on Vulmon Subscribe to Product

exrick xmall 1.1