CVE-2025-8764: linlinjava litemall upload unrestricted upload
A vulnerability classified as critical has been found in linlinjava litemall up to 1.8.0. Affected is the function Upload of the file /wx/storage/upload. The manipulation of the argument File leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
linlinjava litemallto a version that resolves this vulnerability.Fixed in 1.8.0 - Compensating control
Restrict remote access to the upload endpoint/function handling /wx/storage/upload to trusted networks (e.g., via firewall/ACL) until the fixed version is applied.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8764?
CVE-2025-8764 is classified as a critical vulnerability.
What kind of vulnerability is CVE-2025-8764?
CVE-2025-8764 is an unrestricted file upload vulnerability.
How do I fix CVE-2025-8764?
To fix CVE-2025-8764, ensure you update linlinjava litemall to a version newer than 1.8.0.
What file is affected by CVE-2025-8764?
The affected file in CVE-2025-8764 is /wx/storage/upload.
Can CVE-2025-8764 be exploited remotely?
Yes, CVE-2025-8764 can be exploited remotely.