CVE-2025-8191 | macrozheng mall up to 1.0.3 Swagger UI /swagger-ui/index.html configUrl cross site scripting (EUVD-2025-22797 / EDB-52392)
A vulnerability classified as problematic has been found in macrozheng mall up to 1.0.3. Affected by this vulnerability is an unknown functionality of the file /swagger-ui/index.html of the component Swagger UI. The manipulation of the argument configUrl leads to cross site scripting.
This vulnerability is listed as CVE-2025-8191. The attack may be initiated remotely. In addition, an exploit is available.
The vendor deleted the GitHub issue for this vulnerability without any explanation. Afterwards the vendor was contacted early about this disclosure via email but did not respond in any way.