Impact
yshopmall version 3.3 and earlier are affected because the /api/upload endpoint accepts files without validating type or content. Attackers can upload files such as HTML, JSP or executable scripts that, when displayed in a victim’s browser, trigger JavaScript injection or code execution. This classic Cross‑Site Scripting weakness (CWE‑79) can allow an attacker to modify the site’s appearance, steal session information or chain other attacks. The flaw is a clear input validation failure that permits arbitrary script payloads.
Affected Systems
All installations of yshopmall using version 3.3 or lower are vulnerable. The risk applies to any user who engages with the file upload feature, because the uploaded content may be served directly and interpreted by browsers as executable code. The vulnerability is confined to the specific application and its users; there is no immediate threat to the underlying operating system or other components.
Risk and Exploitability
The CVSS score of 6.1 represents moderate severity, while the EPSS score of < 1% indicates a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Based on the description, exploitation requires an attacker to be able to upload a file with sufficient privileges, and the impact is limited to browsers of users who view the malicious content. However, successful XSS could lead to session hijacking, defacement, or further compromise of user accounts.
OpenCVE Enrichment