Impact
Mall4j versions up to 4.0 contain a file upload flaw within the FileController endpoints that fail to enforce proper authorization checks and accept any file type without validation. Attackers who possess an authenticated token can upload files such as HTML or SVG that contain malicious scripts, which are then stored on the server and executed when an administrator accesses them via the local storage path. This results in a stored cross‑site scripting (XSS) payload that targets browsers of users with administrative privileges. The vulnerability does not enable arbitrary code execution on the server, but it fully compromises the confidentiality and integrity of administrative sessions. The weakness corresponds to CWE‑434, Unrestricted Upload of File with Dangerous Type.
Affected Systems
The affected product is Mall4j by gz‑yami, specifically all releases up to and including version 4.0. No further version specifics are provided in the CNA data, so any deployment of Mall4j 4.0 or earlier is considered vulnerable.
Risk and Exploitability
The CVSS score of 2.1 indicates a low severity, yet the exploitability is substantial because any user who can obtain an authenticated token can trigger the upload. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting that large‑scale exploitation has not yet been observed. The attack path involves authenticating to the application, accessing the vulnerable file upload endpoint, and uploading a crafted <script>–bearing HTML or SVG file. Once stored, the payload activates conditionally when an administrator opens the file, leading to XSS; administrators become the attack vector for broader compromise of the application. The overall risk is moderate for environments where administrative privileges are broadly granted or where the upload directory is accessible to users.
OpenCVE Enrichment