CVE-2025-13252 Details
Description
A vulnerability was found in shsuishang ShopSuite ModulithShop up to 45a99398cec3b7ad7ff9383694f0b53339f2d35a. Affected by this issue is some unknown functionality of the component RSA/OAuth2/Database. The manipulation results in hard-coded credentials. The attack can be executed remotely. The exploit has been made public and could be used. This product implements a rolling release for ongoing delivery, which means version information for affected or updated releases is unavailable.
A vulnerability exists in shsuishang ShopSuite ModulithShop versions prior to 45a99398cec3b7ad7ff9383694f0b53339f2d35a, involving hard-coded cryptographic secrets and database credentials within the Java source code. This issue affects the RSA, OAuth2, and database components, posing a significant security risk as these secrets are compiled into the application binary and can be exposed through source code repositories or reverse engineering. The vulnerability allows for the extraction of private keys, impersonation of OAuth2 clients, and unauthorized access to databases, particularly staging or development environments.
It is recommended to rotate all exposed secrets, including RSA keys, OAuth2 client secrets, and database passwords. After rotating the secrets, remove hard-coded credentials from the source code and replace them with configuration injections that load secrets from external sources such as environment variables or secret management tools. Long-term solutions include adopting security-first development practices, establishing code review guidelines, controlling access to production secrets, and securing test code.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Nov 16, 2025CISA-ADP
Assessed Nov 17, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/shsuishang/modulithshop/issues/2 | [email protected] | Issue TrackingTechnical DescriptionVendor |
| https://github.com/shsuishang/modulithshop/issues/2#issue-3580272472 | [email protected] | Issue TrackingTechnical DescriptionVendor |
| https://vuldb.com/?ctiid.332587 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/?id.332587 | [email protected] | AdvisoryExploitPartial Content |
| https://vuldb.com/?submit.687685 | [email protected] | Technical Description |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-259 | Use of Hard-coded Password | [email protected] |
| CWE-798 | Use of Hard-coded Credentials | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| shsuishang ShopSuite ModulithShop | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 29, 2026 | Data Remediation | [email protected] |
| Nov 16, 2025 | New CVE Received | [email protected] |
Volerion