Improper Authentication Management in Linlinjava Litemall Login Endpoint
CVE-2026-105237
Key Information:
- Vendor
Linlinjava
- Status
- Vendor
- CVE Published:
- 5 October 2026
Badges
What is CVE-2026-105237?
A vulnerability exists in Linlinjava Litemall that allows for improper management of excessive authentication attempts at the Login Endpoint. This issue resides within the AdminAuthController.java file, potentially enabling remote attackers to cause a denial of service through excessive login attempts. The exploit complexity is deemed high, suggesting that leveraging this vulnerability requires significant skill. Despite being reported early to the project maintainers, there has been no response, leaving users exposed to potential attacks.
Affected Version(s)
litemall 1.0
litemall 1.1
litemall 1.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
