---
id: CVE-2025-15086
title: A weakness has been identified in youlaitech youlai-mall 1.0.0/2.0.0
summary: >-
  A weakness has been identified in youlaitech youlai-mall 1.0.0/2.0.0. This
  impacts the function getMemberByMobile of the file
  mall-ums/ums-boot/src/main/java/com/youlai/mall/ums/controller/app/MemberController.java.
  This manipulation cau…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-266
  - CWE-284
vendor: youlai
product: youlai-mall
affected:
  - youlai-mall = 1.0.0
  - youlai-mall = 2.0.0
published: '2025-12-25'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T13:10:00.713'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-15086'
references:
  - url: 'https://github.com/Hwwg/cve/issues/27'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?ctiid.338414'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?id.338414'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?submit.708176'
    label: cna@vuldb.com
tags:
  - nvd
epss: 0.003
epssPercentile: 0.20779
ingestedAt: '2026-10-07T13:31:04.569Z'
---

## Overview

A weakness has been identified in youlaitech youlai-mall 1.0.0/2.0.0. This impacts the function getMemberByMobile of the file mall-ums/ums-boot/src/main/java/com/youlai/mall/ums/controller/app/MemberController.java. This manipulation causes improper access controls. The attack may be initiated remotely. The exploit has been made available to the public and could be exploited. The vendor was contacted early about this disclosure but did not respond in any way.

## Affected

- `youlai-mall = 1.0.0`
- `youlai-mall = 2.0.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
