Cross Site Request Forgery (CSRF) vulnerability in old-peanut Open-Shop (aka old-peanut/wechat_applet__open_source) thru 1
Description
Cross Site Request Forgery (CSRF) vulnerability in old-peanut Open-Shop (aka old-peanut/wechat_applet__open_source) thru 1
Remediation
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Executive Summary:
A critical vulnerability has been identified in multiple JeeWMS products, designated as CVE-2025-50901 with a CVSS score of 9.8. This flaw allows an unauthenticated attacker to bypass security controls and read arbitrary files from the underlying server, potentially exposing sensitive data such as configuration files, credentials, and proprietary information. Due to its critical severity and the ease of exploitation, immediate remediation is strongly recommended to prevent a potential data breach.
Vulnerability Details
CVE-ID: CVE-2025-50901
Affected Software: JeeWMS Multiple Products
Affected Versions: Versions including and prior to commit
771e4f5d0c01ffdeae1671be4cf102b73a3fe644. See vendor advisory for specific affected versions.Vulnerability: The vulnerability is an incorrect authentication bypass. A flaw in the application's authentication logic allows a remote, unauthenticated attacker to circumvent access controls. By exploiting this flaw, the attacker can then leverage a file reading function, likely through path traversal, to access and exfiltrate any file on the server's filesystem that the application's user account has permission to read. This could include sensitive application source code, configuration files containing database credentials, system files, and other confidential data.
Business Impact
This vulnerability presents a critical risk to the organization, reflected by its CVSS score of 9.8. Successful exploitation could lead to a severe data breach, resulting in the compromise of sensitive corporate data, customer information (PII), and intellectual property. The exposure of credentials read from configuration files could allow an attacker to pivot and gain deeper access to the internal network, leading to a wider system compromise. Potential consequences include significant financial loss, reputational damage, regulatory penalties, and loss of customer trust.
Remediation Plan
Immediate Action: The highest priority is to apply the security patches provided by the vendor.
Proactive Monitoring:
../,..%2f).Compensating Controls: If patching cannot be performed immediately, implement the following controls to reduce risk:
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of the publication date of this advisory (Aug 20, 2025), there are no known public proof-of-concept exploits or active exploitation campaigns targeting this vulnerability. However, given the critical severity (9.8) and the nature of the flaw (unauthenticated remote file read), it is highly probable that threat actors will develop exploits in the near future.
Analyst Recommendation
Given the critical severity of CVE-2025-50901, this vulnerability requires immediate attention. The potential for a complete compromise of sensitive data by an unauthenticated attacker makes it a top-priority target for remediation. Although it is not currently listed on the CISA KEV catalog, its high-impact nature makes it a likely candidate for future inclusion. We strongly recommend that organizations apply the vendor-supplied updates to all affected JeeWMS products without delay to mitigate this significant risk.