A vulnerability in the XiaozhangBang Voluntary Like System V8.8 allows remote attackers to manipulate the zhekou parameter in the /topfirst.php Pay module, enabling unauthorized discounts. By sending a crafted HTTP POST request with zhekou set to an abnormally low value, an attacker can purchase votes at a reduced cost. Furthermore, by modifying the zid parameter, attackers can influence purchases made by other users, amplifying the impact. This issue stems from insufficient server-side validation of these parameters, potentially leading to economic loss and unfair manipulation of vote counts.
Metrics
Affected Vendors & Products
References
History
Thu, 06 Nov 2025 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Xiaozhangbang
Xiaozhangbang voluntary Like System |
|
| Vendors & Products |
Xiaozhangbang
Xiaozhangbang voluntary Like System |
Wed, 05 Nov 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 CWE-285 |
|
| Metrics |
cvssV3_1
|
Wed, 05 Nov 2025 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability in the XiaozhangBang Voluntary Like System V8.8 allows remote attackers to manipulate the zhekou parameter in the /topfirst.php Pay module, enabling unauthorized discounts. By sending a crafted HTTP POST request with zhekou set to an abnormally low value, an attacker can purchase votes at a reduced cost. Furthermore, by modifying the zid parameter, attackers can influence purchases made by other users, amplifying the impact. This issue stems from insufficient server-side validation of these parameters, potentially leading to economic loss and unfair manipulation of vote counts. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2025-11-05T00:00:00.000Z
Updated: 2025-11-05T21:01:51.302Z
Reserved: 2025-09-26T00:00:00.000Z
Link: CVE-2025-60784
Updated: 2025-11-05T21:00:13.943Z
Status : Received
Published: 2025-11-05T21:15:35.903
Modified: 2025-11-05T21:15:35.903
Link: CVE-2025-60784
No data.