Improper Authorization Vulnerability in Linlinjava Litemall Version 1.8.0
CVE-2025-6702
Key Information:
- Vendor
Linlinjava
- Status
- Vendor
- CVE Published:
- 26 June 2025
Badges
What is CVE-2025-6702?
A significant vulnerability exists in Linlinjava's Litemall version 1.8.0, specifically targeting the function within the /wx/comment/post file. This flaw arises from the improper handling of the 'adminComment' argument, which can allow unauthorized users to perform actions that should be restricted. The vulnerability is exploitable remotely, posing a critical risk as the exploit has been published publicly. Efforts to alert the vendor regarding this weakness have gone unanswered, raising concerns for users relying on this software version.
Affected Version(s)
litemall 1.8.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved