CVE-2026-15753 Details
Description
A vulnerability was determined in zhinianboke xianyu-auto-reply on Server. Affected by this vulnerability is an unknown functionality of the file /api/v1/payment/withdraw/review?action=approve. Executing a manipulation can lead to trusting http permission methods on the server side. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. This patch is called 19fc3282a1bb78a05c34945c088525d20e081cbd. It is best practice to apply a patch to resolve this issue.
A vulnerability exists in the zhinianboke xianyu-auto-reply application, specifically within the backend Web API service. The issue arises in the payment withdrawal review endpoint, which is part of the application's financial transaction management. This vulnerability allows for unauthorized manipulation of withdrawal review actions, potentially leading to improper approval of withdrawal requests. The flaw can be exploited remotely, creating a risk of financial misconduct within the application.
The vulnerability has been fixed in the latest commit. It is recommended to update to the version that includes this fix.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 14, 2026CISA-ADP
Assessed Jul 15, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/zhinianboke/xianyu-auto-reply/ | [email protected] | Source CodeVendor |
| https://github.com/zhinianboke/xianyu-auto-reply/commit/19fc3282a1bb78a05c34945c088525d20e081cbd | [email protected] | Source CodeVendor |
| https://github.com/zhinianboke/xianyu-auto-reply/issues/192 | [email protected] | ExploitIssue TrackingRemedyTechnical AnalysisVendor |
| https://vuldb.com/cve/CVE-2026-15753 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/856719 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/378335 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/378335/cti | [email protected] | AdvisoryContent Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-650 | Trusting HTTP Permission Methods on the Server Side | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| zhinianboke xianyu-auto-reply | <= 04580d6490b4731d0055f29736930d8cc59b60d6 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 15, 2026 | CVE Modified | CISA-ADP |
| Jul 14, 2026 | New CVE Received | [email protected] |
Volerion