Description
yshopmall <=3.3 is vulnerable to Cross Site Scripting (XSS). The file upload endpoint /api/upload of the system lacks file type validation. Attackers can upload files of any type, including HTML, JSP, and other executable files.
Published: 2026-09-09
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑Site Scripting
Action: Monitor
AI Analysis

Impact

yshopmall version 3.3 and earlier are affected because the /api/upload endpoint accepts files without validating type or content. Attackers can upload files such as HTML, JSP or executable scripts that, when displayed in a victim’s browser, trigger JavaScript injection or code execution. This classic Cross‑Site Scripting weakness (CWE‑79) can allow an attacker to modify the site’s appearance, steal session information or chain other attacks. The flaw is a clear input validation failure that permits arbitrary script payloads.

Affected Systems

All installations of yshopmall using version 3.3 or lower are vulnerable. The risk applies to any user who engages with the file upload feature, because the uploaded content may be served directly and interpreted by browsers as executable code. The vulnerability is confined to the specific application and its users; there is no immediate threat to the underlying operating system or other components.

Risk and Exploitability

The CVSS score of 6.1 represents moderate severity, while the EPSS score of < 1% indicates a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Based on the description, exploitation requires an attacker to be able to upload a file with sufficient privileges, and the impact is limited to browsers of users who view the malicious content. However, successful XSS could lead to session hijacking, defacement, or further compromise of user accounts.

Generated by OpenCVE AI on September 21, 2026 at 05:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Enforce strict MIME type and file extension checks on the /api/upload endpoint, rejecting any files that are not approved image or document types.
  • If an updated, non‑vulnerable release of yshopmall is available, upgrade immediately to that version.
  • Store uploaded files outside the web root and serve them through a dedicated download handler that validates the requesting user’s permissions and sanitizes the content to prevent inline script execution.

Generated by OpenCVE AI on September 21, 2026 at 05:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Mon, 21 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Title Cross‑Site Scripting via Unvalidated File Upload in yshopmall

Mon, 14 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
Title Cross‑Site Scripting via Unvalidated File Upload in yshopmall
Weaknesses CWE-79

Wed, 09 Sep 2026 21:45:00 +0000

Type Values Removed Values Added
Description yshopmall <=3.3 is vulnerable to Cross Site Scripting (XSS). The file upload endpoint /api/upload of the system lacks file type validation. Attackers can upload files of any type, including HTML, JSP, and other executable files.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-14T12:31:36.620Z

Reserved: 2026-08-17T00:00:00.000Z

Link: CVE-2026-75308

cve-icon Vulnrichment

Updated: 2026-09-14T12:30:29.489Z

cve-icon NVD

Status : Deferred

Published: 2026-09-09T22:18:28.857

Modified: 2026-09-14T13:18:46.127

Link: CVE-2026-75308

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T06:00:09Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')