CVE-2025-13246

Published
View on NVD ↗
CVSS v3
6.3
MEDIUM
CVSS v2
6.5
MEDIUM
Affected
1
PROJECT

Description

A vulnerability was identified in shsuishang ShopSuite ModulithShop up to 45a99398cec3b7ad7ff9383694f0b53339f2d35a. Impacted is the function JwtAuthenticationFilter of the file src/main/java/com/suisung/shopsuite/common/security/JwtAuthenticationFilter.java. The manipulation leads to path traversal. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available.

ModulithShop是Java商城系统,采用Java+Springboot+Vue+Uniapp商城框架的开源电商Java系统(除了java商城外,还开源了go商城及php商城),能满足B2C商城,新零售商城,社交电商Java商城,分销商城,微信小程序商城,B2B商城系统等多种模式Java商城项目。
GitHubGitHub
53