PT-2026-41592 · Linlinjava · Litemall
Berna
·
Published
2026-05-18
·
Updated
2026-05-18
·
CVE-2026-8773
CVSS v2.0
5.8
Medium
| Vector | AV:N/AC:L/Au:M/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
linlinjava litemall versions prior to 1.8.1
Description
An argument injection issue exists in the Database Setting Handler component. The
backup/load function within the file litemall-db/src/main/java/org/linlinjava/litemall/db/util/DbUtil.java is susceptible to remote attacks via the manipulation of the db/password argument.Recommendations
Update to a version later than 1.8.0.
As a temporary workaround, restrict access to the
backup/load function in the DbUtil.java file to minimize the risk of exploitation.Exploit
Fix
Argument Injection
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Litemall