PT-2026-6973 · Guchengwuyue · Yshopmall
Mukyuuhate
·
Published
2026-02-08
·
Updated
2026-02-08
·
CVE-2026-2146
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
guchengwuyue yshopmall versions up to 1.9.1
Description
A security flaw exists in guchengwuyue yshopmall up to version 1.9.1. The issue is related to unrestricted upload, stemming from manipulation of the
File argument within the updateAvatar function located in the file '/api/users/updateAvatar' of the co.yixiang.utils.FileUtil component. This allows for remote exploitation. The exploit has been publicly released. The project maintainers were notified of the issue but have not yet responded.Recommendations
Versions prior to 1.9.1 should be used. As a temporary workaround, consider restricting file upload capabilities until a patch is available.
Exploit
Fix
Unrestricted File Upload
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Yshopmall