Cross-Site Scripting Vulnerability in Linlinjava Litemall Product Detail Service
CVE-2026-90570
4.8MEDIUM
What is CVE-2026-90570?
A cross-site scripting vulnerability exists in the AdminGoodsService.validate function within the product detail component of Linlinjava Litemall versions 1.4.0 to 1.8.0. The issue arises from improper handling of user input, which allows an attacker to execute arbitrary JavaScript in the context of the user's browser. This can lead to unauthorized actions, data exposure, or session hijacking. As the attack can be executed remotely, it poses a significant risk to users. The vendor has been notified about the vulnerability following an issue report but has yet to address the matter.
Affected Version(s)
litemall 1.4.0
litemall 1.5.0
litemall 1.6.0
