Impact
The vulnerability in linlinjava litemall arises from inadequate limitation of authentication attempts within the Login Endpoint AdminAuthController. This flaw allows an attacker to repeatedly submit credentials without restriction, increasing the probability of successfully guessing valid credentials. The weakness is identified as CWE-307 and CWE-799, corresponding to insufficient authentication and improper access control. Although no remote code execution is possible, an attacker who can repeatedly attempt logins may compromise user accounts and gain unauthorized administrative access, affecting confidentiality and integrity of the system.
Affected Systems
All installations of linlinjava litemall up to version 1.8.0 are affected. The attack vector is remote, targeting the exposed login API endpoint of the AdminAuthController. Vendors should verify which patch versions include a fix; the issue is reported but no response has yet been provided.
Risk and Exploitability
The CVSS score of 6.3 indicates moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The exploitability is described as high complexity and difficult, yet the exploit is now public. Based on the description, it is inferred that an attacker from a remote location can exploit this weakness by performing continuous authentication attempts, potentially leading to account compromise if no lockout or rate‑limiting controls are in place.
OpenCVE Enrichment