CNNVD-202508-2202 Information

CNNVD ID

CNNVD-202508-2202

CVE-2025-52338

  • CNNVD Published: 2025-08-19

Description (Chinese)

LogicData eCommerce Framework是美国LogicData公司的一款电子商务中间件。 LogicData eCommerce Framework v5.0.9.7000版本存在安全漏洞,该漏洞源于密码重置功能默认配置不当,可能导致绕过身份验证和暴力破解攻击。

Description (English)

LogicData eCommerce Framework is an e-commerce intermediary of the United States company LogicData. There is a security loophole in the LogicData eCommerce Framework v5.0.9.7000 version, which arises from the inappropriate default configuration of the password reset function, which may lead to bypassing identification and violent break-up attacks.

Hazard Level

High

Vulnerability Type

其他

Affected Vendor

LogicData

Published

2025-08-19

Last Modified

2026-02-24

References

https://cwe.mitre.org/data/definitions/522.html https://cwe.mitre.org/data/definitions/521.html https://github.com/TrustStackSecurity/Advisories/tree/main/CVE-2025-52338 https://www.logicdata.com/products/webstore-for-erp-ecommerce-integration/ https://nvd.nist.gov/vuln/detail/CVE-2025-52338

Share on: