Linlinjava

Litemall

17 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.24%
  • Veröffentlicht 09.08.2025 18:32:06
  • Zuletzt bearbeitet 29.04.2026 01:00:01

A vulnerability classified as critical has been found in linlinjava litemall up to 1.8.0. Affected is the function Upload of the file /wx/storage/upload. The manipulation of the argument File leads to unrestricted upload. It is possible to launch the...

Exploit
  • EPSS 0.5%
  • Veröffentlicht 09.08.2025 13:32:05
  • Zuletzt bearbeitet 29.04.2026 01:00:01

A vulnerability, which was classified as critical, has been found in linlinjava litemall up to 1.8.0. Affected by this issue is the function delete of the file /admin/storage/delete of the component File Handler. The manipulation of the argument key ...

Exploit
  • EPSS 0.33%
  • Veröffentlicht 26.06.2025 16:00:16
  • Zuletzt bearbeitet 29.04.2026 01:00:01

A vulnerability, which was classified as problematic, was found in linlinjava litemall 1.8.0. Affected is an unknown function of the file /wx/comment/post. The manipulation of the argument adminComment leads to improper authorization. It is possible ...

Exploit
  • EPSS 0.63%
  • Veröffentlicht 19.09.2024 13:15:04
  • Zuletzt bearbeitet 29.04.2026 11:16:02

A SQL injection vulnerability in linlinjava litemall 1.8.0 allows a remote attacker to obtain sensitive information via the goodsId, goodsSn, and name parameters in AdminOrderController.java.

Exploit
  • EPSS 0.48%
  • Veröffentlicht 02.07.2024 20:15:06
  • Zuletzt bearbeitet 11.09.2025 15:08:44

A vulnerability classified as critical was found in linlinjava litemall up to 1.8.0. Affected by this vulnerability is an unknown functionality of the file AdminGoodscontroller.java. The manipulation of the argument goodsId/goodsSn/name leads to sql ...

Exploit
  • EPSS 0.72%
  • Veröffentlicht 27.02.2024 17:15:12
  • Zuletzt bearbeitet 15.09.2025 17:09:47

SQL injection vulnerability in linlinjava litemall v.1.8.0 allows a remote attacker to obtain sensitive information via the nickname, consignee, orderSN, orderStatusArray parameters of the AdminOrdercontroller.java component.

  • EPSS 2.35%
  • Veröffentlicht 17.10.2018 06:29:00
  • Zuletzt bearbeitet 11.09.2025 17:19:20

An issue was discovered in litemall 0.9.0. Arbitrary file download is possible via ../ directory traversal in linlinjava/litemall/wx/web/WxStorageController.java in the litemall-wx-api component.