YunzMall Password Recovery Vulnerability in ResetpwdController.php

Vulnerability

A critical vulnerability exists in YunzMall versions through 2.4.2, specifically in the password recovery function of the ResetpwdController.php file. This issue arises from the HTTP POST request handling, where improper manipulation of the password argument enables weak password recovery. The vulnerability can be exploited remotely.

Impact

Exploitation of this vulnerability allows for weak password recovery, potentially leading to unauthorized access.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
8.7
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.