Metrics
Affected Vendors & Products
Thu, 06 Nov 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jerryshensjf
Jerryshensjf jpacookieshop |
|
| CPEs | cpe:2.3:a:jerryshensjf:jpacookieshop:-:*:*:*:*:*:*:* | |
| Vendors & Products |
Jerryshensjf
Jerryshensjf jpacookieshop |
Tue, 22 Jul 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 21 Jul 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was found in jerryshensjf JPACookieShop 蛋糕商城JPA版 1.0 and classified as critical. This issue affects the function updateGoods of the file GoodsController.java. The manipulation leads to authorization bypass. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. | |
| Title | jerryshensjf JPACookieShop 蛋糕商城JPA版 GoodsController.java updateGoods authorization | |
| Weaknesses | CWE-285 CWE-639 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2025-07-21T20:02:05.704Z
Updated: 2025-07-22T16:04:37.544Z
Reserved: 2025-07-21T07:13:44.028Z
Link: CVE-2025-7938
Updated: 2025-07-22T16:04:34.401Z
Status : Analyzed
Published: 2025-07-21T20:15:56.803
Modified: 2025-11-06T16:12:01.390
Link: CVE-2025-7938
No data.