Impact
The vulnerability is a SQL injection in an unidentified admin function of linlinjava litemall, enabling remote attackers to run arbitrary SQL statements. This could lead to unauthorized data disclosure, tampering, or loss. The flaw is catalogued as CWE-74 and CWE-89, indicating improper neutralization of special elements and classic SQL injection weaknesses.
Affected Systems
linlinjava litemall versions up to 1.8.0 are affected, with multiple admin endpoints vulnerable. The specific function is not named in the advisory, but any exposed admin route may present the flaw.
Risk and Exploitability
The CVSS score of 5.1 denotes a moderate severity. EPSS data is unavailable, and the vulnerability is not listed in the CISA KEV registry, though public exploit code exists. Attackers can exploit the vulnerability remotely via malicious requests to the affected admin endpoints, potentially gaining significant database access.
OpenCVE Enrichment