Vulnerability Description
A vulnerability was identified in shsuishang ShopSuite ModulithShop up to 45a99398cec3b7ad7ff9383694f0b53339f2d35a. Impacted is the function JwtAuthenticationFilter of the file src/main/java/com/suisung/shopsuite/common/security/JwtAuthenticationFilter.java. The manipulation leads to path traversal. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/shsuishang/modulithshop/issues/1
- https://vuldb.com/?ctiid.332580
- https://vuldb.com/?id.332580
- https://vuldb.com/?submit.687532
FAQ
What is CVE-2025-13246?
CVE-2025-13246 is a vulnerability with a CVSS score of 6.3 (MEDIUM). A vulnerability was identified in shsuishang ShopSuite ModulithShop up to 45a99398cec3b7ad7ff9383694f0b53339f2d35a. Impacted is the function JwtAuthenticationFilter of the file src/main/java/com/suisu...
How severe is CVE-2025-13246?
CVE-2025-13246 has been rated MEDIUM with a CVSS base score of 6.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-13246?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.