PT-2025-32451 · Linlinjava · Litemall

Ez-Lbz

·

Published

2025-08-09

·

Updated

2025-08-12

·

CVE-2025-8764

CVSS v3.1

6.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions: linlinjava litemall versions prior to 1.8.1
Description: A critical issue exists in linlinjava litemall up to version 1.8.0. The Upload function within the /wx/storage/upload file is susceptible to unrestricted file upload due to manipulation of the File argument. This allows for remote exploitation. The exploit details have been publicly disclosed.
Recommendations: Update linlinjava litemall to version 1.8.1 or later. As a temporary workaround, restrict access to the /wx/storage/upload file.

Exploit

Fix

Improper Access Control

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2025-8764

Affected Products

Litemall