TIME-SEA-PLUS Order Status Improper Auth in alipayIsSucceed
CVE-2025-12304 Published on October 27, 2025

dulaiduwang003 TIME-SEA-PLUS Order Status PayController.java alipayIsSucceed improper authorization
A vulnerability has been found in dulaiduwang003 TIME-SEA-PLUS up to fb299162f18498dd9cf17da906886d80a077d53b. This affects the function alipayIsSucceed of the file PayController.java of the component Order Status Handler. The manipulation leads to improper authorization. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.

NVD

Timeline

Advisory disclosed

VulDB entry created

VulDB entry last update

Weakness Types

What is an AuthZ Vulnerability?

The software does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

CVE-2025-12304 has been classified to as an AuthZ vulnerability or weakness.

Incorrect Privilege Assignment

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.


Products Associated with CVE-2025-12304

Want to know whenever a new CVE is published for Dulaiduwang003 Time Sea Plus? stack.watch will email you.

 

Affected Versions

dulaiduwang003 TIME-SEA-PLUS Version fb299162f18498dd9cf17da906886d80a077d53b is affected by CVE-2025-12304

Exploit Probability

EPSS
0.03%
Percentile
9.57%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.