CVE-2025-13252 - CVE House
Back to Database
Status published Medium CVE-2025-13252

shsuishang ShopSuite ModulithShop RSA/OAuth2/Database hard-coded credentials

Vulnerability Description

A vulnerability was found in shsuishang ShopSuite ModulithShop up to 45a99398cec3b7ad7ff9383694f0b53339f2d35a. Affected by this issue is some unknown functionality of the component RSA/OAuth2/Database. The manipulation results in hard-coded credentials. The attack can be executed remotely. The exploit has been made public and could be used. This product implements a rolling release for ongoing delivery, which means version information for affected or updated releases is unavailable.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-13252

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • ez-lbz (VulDB User)

Affected Vendor

Affected Software

ShopSuite ModulithShop
Vulnerable Versions:
45a99398cec3b7ad7ff9383694f0b53339f2d35a

Timeline

Official Publish: November 16th, 2025
Last Modified: November 17th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R

Weaknesses (CWE)