Cross Site Scripting Vulnerability in newbee-ltd newbee-mall Product
CVE-2026-94045

5.1MEDIUM

Key Information:

Vendor

Newbee-ltd

Vendor
CVE Published:
20 September 2026

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2026-94045?

A significant security flaw has been identified in the newbee-ltd newbee-mall application, specifically within the UploadController.java file responsible for handling goods data. This vulnerability allows for the manipulation of the 'goodsName' parameter, facilitating cross site scripting (XSS) attacks remotely. As a result, attackers can exploit this weakness to insert malicious scripts into the application, potentially compromising user data and application integrity. The flaw bypasses the 'image-only' guard due to ImageIO.read() handling polyglot payloads, making it possible for persisted XSS attacks instead of one-time scripts. Despite being informed of the vulnerability through an issue report, the vendor has yet to provide a resolution.

Affected Version(s)

newbee-mall 1.0

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

rockmelodeis (VulDB User)
VulDB CNA Team
.