CVE-2026-102366
LOW
2,1
Source: [email protected]
Attack Vector: network
Attack Complexity: low
Privileges Required: low
User Interaction: passive
Confidentiality: N/A
Integrity: N/A
Availability: N/A
MEDIUM
4,4
Source: [email protected]
Attack Vector: network
Attack Complexity: high
Privileges Required: low
User Interaction: required
Scope: changed
Confidentiality: low
Integrity: low
Availability: none
Description
AI Translation Available
mall4j through 4.0 contains an unrestricted file upload vulnerability in FileController endpoints that lack authorization checks and accept arbitrary file types without validation. Attackers with any authenticated token can upload HTML or SVG files that execute scripts in administrator browsers when accessed from the local storage path, resulting in stored cross-site scripting.
434
Unrestricted Upload of File with Dangerous Type
DraftCommon Consequences
Security Scopes Affected:
Integrity
Confidentiality
Availability
Potential Impacts:
Execute Unauthorized Code Or Commands
Applicable Platforms
Languages:
ASP.NET, PHP, Not Language-Specific
Technologies:
Web Server, AI/ML
https://github.com/gz-yami/mall4j
https://github.com/gz-yami/mall4j/blob/ffc672fc1aa4320ce02d0b93853bb456ae0a4dae…
https://github.com/gz-yami/mall4j/blob/ffc672fc1aa4320ce02d0b93853bb456ae0a4dae…
https://github.com/LinYuanyi1/cve-request-poc/blob/114b3f0d149e50a7678f591bf804…
https://www.vulncheck.com/advisories/mall4j-through-4.0-unrestricted-file-uploa…