PT-2025-33303 · Linlinjava · Litemall

Zast.Ai

·

Published

2025-08-14

·

Updated

2025-08-14

·

CVE-2025-8965

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: linlinjava litemall versions up to 1.8.0
Description: A vulnerability exists in linlinjava litemall up to version 1.8.0, specifically within the create function located in the file litemall-admin-api/src/main/java/org/linlinjava/litemall/admin/web/AdminStorageController.java of the Endpoint component. The vulnerability is due to unrestricted upload caused by manipulation of the File argument. This issue can be exploited remotely. The exploit has been publicly disclosed.
Recommendations: linlinjava litemall versions prior to 1.8.0 are recommended. As a temporary workaround, consider restricting file upload permissions.

Exploit

Fix

Improper Access Control

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2025-8965

Affected Products

Litemall