Impact
The flaw is a cross‑site scripting vulnerability located in the AdminGoodsService.validate function of litemall's Product Detail component. By manipulating the 'detail' argument, an attacker can cause arbitrary JavaScript to execute in the browser when a user views the affected page, enabling tampering with page content or unintended actions. This is a client‑side issue that does not provide direct server‑side code execution but can be used to subvert the user experience and potentially exfiltrate session data.
Affected Systems
linlinjava litemall versions 1.4.0 through 1.8.0 are affected, specifically the file litemall-vue/src/views/items/detail/index.vue. The vulnerability is present in each major release listed and may impact any deployment that uses these versions.
Risk and Exploitability
The CVSS v3 score of 4.8 indicates medium severity, and the EPSS score of less than 1% suggests a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The description states that the attack can be launched remotely by providing a crafted 'detail' value, but it is not explicitly stated whether the AdminGoodsService endpoint is externally reachable; the remote exploitation statement is inferred from the wording "launched remotely." The flaw can be triggered by sending a malicious value to the 'detail' parameter of the AdminGoodsService.validate request from an authenticated or unauthenticated user depending on the application's design. No privileged or server‑side code execution is required.
OpenCVE Enrichment