Description
A vulnerability has been found in linlinjava litemall 1.4.0/1.5.0/1.6.0/1.7.0/1.8.0. This issue affects the function AdminGoodsService.validate of the file litemall-vue/src/views/items/detail/index.vue of the component Product Detail. Such manipulation of the argument detail leads to cross site scripting. The attack may be launched remotely. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-09-13
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑Site Scripting
Action: Apply Patch
AI Analysis

Impact

The flaw is a cross‑site scripting vulnerability located in the AdminGoodsService.validate function of litemall's Product Detail component. By manipulating the 'detail' argument, an attacker can cause arbitrary JavaScript to execute in the browser when a user views the affected page, enabling tampering with page content or unintended actions. This is a client‑side issue that does not provide direct server‑side code execution but can be used to subvert the user experience and potentially exfiltrate session data.

Affected Systems

linlinjava litemall versions 1.4.0 through 1.8.0 are affected, specifically the file litemall-vue/src/views/items/detail/index.vue. The vulnerability is present in each major release listed and may impact any deployment that uses these versions.

Risk and Exploitability

The CVSS v3 score of 4.8 indicates medium severity, and the EPSS score of less than 1% suggests a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The description states that the attack can be launched remotely by providing a crafted 'detail' value, but it is not explicitly stated whether the AdminGoodsService endpoint is externally reachable; the remote exploitation statement is inferred from the wording "launched remotely." The flaw can be triggered by sending a malicious value to the 'detail' parameter of the AdminGoodsService.validate request from an authenticated or unauthenticated user depending on the application's design. No privileged or server‑side code execution is required.

Generated by OpenCVE AI on September 15, 2026 at 17:13 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the official update that supplies a fixed version of litemall when it becomes available.
  • Implement server‑side filtering or proper escaping for the 'detail' parameter to neutralize any embedded script content before rendering it in the page.
  • Enforce a strict content‑security‑policy header and enable X‑XSS‑Protection to mitigate the impact of residual client‑side injection.

Generated by OpenCVE AI on September 15, 2026 at 17:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 13 Sep 2026 17:00:00 +0000

Type Values Removed Values Added
Description A vulnerability has been found in linlinjava litemall 1.4.0/1.5.0/1.6.0/1.7.0/1.8.0. This issue affects the function AdminGoodsService.validate of the file litemall-vue/src/views/items/detail/index.vue of the component Product Detail. Such manipulation of the argument detail leads to cross site scripting. The attack may be launched remotely. The project was informed of the problem early through an issue report but has not responded yet.
Title linlinjava litemall Product Detail index.vue AdminGoodsService.validate cross site scripting
First Time appeared Linlinjava
Linlinjava litemall
Weaknesses CWE-79
CWE-94
CPEs cpe:2.3:a:linlinjava:litemall:*:*:*:*:*:*:*:*
Vendors & Products Linlinjava
Linlinjava litemall
References
Metrics cvssV2_0

{'score': 3.3, 'vector': 'AV:N/AC:L/Au:M/C:N/I:P/A:N/E:ND/RL:ND/RC:UR'}

cvssV3_0

{'score': 2.4, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N/E:X/RL:X/RC:R'}

cvssV3_1

{'score': 2.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N/E:X/RL:X/RC:R'}

cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X'}


Subscriptions

Linlinjava Litemall
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-16T14:12:33.189Z

Reserved: 2026-09-12T16:03:25.474Z

Link: CVE-2026-90570

cve-icon Vulnrichment

Updated: 2026-09-16T14:12:28.314Z

cve-icon NVD

Status : Deferred

Published: 2026-09-13T17:16:57.987

Modified: 2026-09-16T15:18:30.560

Link: CVE-2026-90570

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T17:15:14Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

  • CWE-94

    Improper Control of Generation of Code ('Code Injection')