CVE-2025-12919

LOW

EverShop <2.0.1 - Info Disclosure

Title source: llm
STIX 2.1

Description

A vulnerability was detected in EverShop up to 2.0.1. Affected is an unknown function of the file /src/modules/oms/graphql/types/Order/Order.resolvers.js of the component Order Handler. The manipulation of the argument uuid results in improper control of resource identifiers. The attack may be performed from remote. This attack is characterized by high complexity. The exploitability is told to be difficult. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry technical-description
https://vuldb.com/?id.331639
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.331639
Third Party Advisory, VDB Entry third-party-advisory
https://vuldb.com/?submit.680788

Scores

CVSS v3 3.7
EPSS 0.0005
EPSS Percentile 16.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-639 CWE-99
Status published
Products (2)
evershop/evershop < 2.0.1
evershop/evershop 0npm
Published Nov 09, 2025
Tracked Since Feb 18, 2026