Impact
The flaw exists in the AdminTopicController.validate endpoint of the litemall administrative interface. An attacker can supply crafted input that is reflected into the topic page without proper escaping, resulting in a cross‑site scripting vulnerability that can be triggered remotely.
Affected Systems
Affected software is the litemall e‑commerce platform from linlinjava, specifically versions 1.5.0, 1.6.0, 1.7.0 and 1.8.0. No other vendors or product lines are listed.
Risk and Exploitability
The base score of 4.8 indicates moderate severity. The EPSS score is very low (<1%) and the vulnerability is not listed in the CISA KEV catalog, suggesting limited public exploitation at the time of analysis. The attack vector is remote, requiring a specially crafted request to the validate endpoint. Based on the description, unsanitized user input may be reflected into the browser, resulting in script execution when a user views the affected topic page.
OpenCVE Enrichment