A security flaw has been discovered in linlinjava litemall up to 1.8.0
A SQL injection vulnerability in Linlinjava Litemall's Front-end WeChat API allows an attacker to execute arbitrary SQL queries. This can be exploited remotely and has been publicly disclosed. The vulnerability has a high CVSS score, indicating a significant risk.
A security flaw has been discovered in linlinjava litemall up to 1.8.0. This impacts the function list of the file litemall-wx-api/src/main/java/org/linlinjava/litemall/wx/web/WxGoodsController.java of the component Front-end WeChat API. Performing a manipulation results in sql injection. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Developers using Linlinjava Litemall are at high risk of a SQL injection attack, which can lead to unauthorized data access and modification.
Remediation Recommended
This vulnerability carries significant risk. Schedule patching in your next cycle.
What should I do?
Published
CVE disclosed publicly
Last Modified
Most recent update
Indexed to CVEInsight
Added to this platform
AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
0
Affected Products
4
References
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Exploitability
Impact