PatchSiren

macrozheng CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW macrozheng CVE published 2026-08-09

CVE-2026-19361

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-09T18:16:42.930Z and has not been modified since then. The vulnerability affects macrozheng mall 0504e86, specifically in the /sso/getAuthCode file of the mall-portal module, potentially leading to weak password recovery. The attack may be launched remotely with high complexity and difficult exploit [truncated]

MEDIUM macrozheng CVE published 2026-05-29

CVE-2026-10070

A medium-severity improper authorization vulnerability exists in macrozheng mall versions up to 1.0.3. The vulnerability resides in the Super Admin Password Handler component, specifically affecting the /admin/update/ endpoint. Remote exploitation is possible through manipulation of this endpoint, allowing an attacker with high privileges to bypass intended authorization controls. The CVSS 4.0 vector indi [truncated]

CRITICAL Macrozheng CVE published 2026-02-07

CVE-2026-25858

CVE-2026-25858 is a critical authentication vulnerability in macrozheng mall version 1.0.3 and prior. The vulnerability allows unauthenticated attackers to reset arbitrary user account passwords using only a victim's telephone number. The password reset flow exposes the one-time password (OTP) directly in the API response and validates password reset requests solely by comparing the provided OTP to a valu [truncated]