NA
CVSSv3

CVE-2025-28399

CVSSv4: NA | CVSSv3: NA | CVSSv2: NA | VMScore: NA | EPSS: 0.00158 | KEV: Not Included
Published: 15/04/2025 Updated: 16/04/2025

Vulnerability Summary

Privilege Escalation in Erick xmall v1.1 via Address Controller Method

An issue in Erick xmall v.1.1 and before allows a remote malicious user to escalate privileges via the updateAddress method of the Address Controller class.