CVE-2025-8965: linlinjava litemall Endpoint AdminStorageController.java create unrestricted upload
A vulnerability has been found in linlinjava litemall up to 1.8.0. This vulnerability affects the function create of the file litemall-admin-api/src/main/java/org/linlinjava/litemall/admin/web/AdminStorageController.java of the component Endpoint. The manipulation of the argument File leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8965?
CVE-2025-8965 has a high severity due to the potential for unauthorized access and manipulation of sensitive data.
How do I fix CVE-2025-8965?
To fix CVE-2025-8965, update the linlinjava litemall to version 1.8.1 or later.
What components are affected by CVE-2025-8965?
CVE-2025-8965 affects the AdminStorageController.java file found in the linlinjava litemall up to version 1.8.0.
How can I mitigate the risks associated with CVE-2025-8965?
Mitigate the risks from CVE-2025-8965 by implementing proper access controls and regularly updating your software.
What functionality is compromised in CVE-2025-8965?
CVE-2025-8965 compromises the functionality of the create method in the Endpoint component, allowing possible exploitation.