Impact
The litemall front‑end WeChat API contains a flaw in WxGoodsController that allows an attacker to inject arbitrary SQL statements when calling the list function. The vulnerability arises from inadequate input validation, leading to execution of unexpected database commands. The impact could include exposure or modification of sensitive application data and is classified under CWE‑74 and CWE‑89.
Affected Systems
All installations of linlinjava litemall version 1.8.0 and earlier are affected. The vulnerability resides in the litemall‑wx‑api component, specifically in the file WxGoodsController.java, which is part of the public Web‑API layer. No vendor‑supplied patch is currently available and the vendor has not acknowledged the issue.
Risk and Exploitability
The CVSS score of 6.9 indicates a medium‑to‑high severity risk. Remote exploitation is possible, and an exploit has already been released publicly, making the security risk real. Because the EPSS score is not available, the exact likelihood of attack is uncertain, but the public availability of the exploit means that attackers will likely target vulnerable deployments. The vulnerability is not listed in the CISA KEV catalog at this time.
OpenCVE Enrichment