CVE-2025-8974: linlinjava litemall JSON Web Token JwtHelper.java hard-coded credentials

Published Aug 14, 2025
·
Updated

A vulnerability was determined in linlinjava litemall up to 1.8.0. Affected by this issue is some unknown functionality of the file litemall-wx-api/src/main/java/org/linlinjava/litemall/wx/util/JwtHelper.java of the component JSON Web Token Handler. The manipulation of the argument SECRET with the input X-Litemall-Token leads to hard-coded credentials. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used.

Affected Software

2 affected components
linlinjava litemall<=1.8.0
linlinjava litemall<=1.8.0

Event History

Aug 14, 2025
CVE Published
via MITRE·06:02 PM
Data Sourced
via MITRE·06:02 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Jun 14, 57923
Event
via FIRST·10:08 PM

Frequently Asked Questions

1

What is the severity of CVE-2025-8974?

CVE-2025-8974 has been assessed with a medium severity rating due to potential impacts on security through improper handling of JSON Web Tokens.

2

How do I fix CVE-2025-8974?

To mitigate CVE-2025-8974, upgrade linlinjava litemall to version 1.8.1 or later, as these versions contain patches for this vulnerability.

3

What vulnerability affects linlinjava litemall up to version 1.8.0?

CVE-2025-8974 affects linlinjava litemall versions up to 1.8.0, impacting the JSON Web Token Handler component.

4

What components are impacted by CVE-2025-8974?

CVE-2025-8974 specifically impacts the JwtHelper.java file within the litemall-wx-api component of linlinjava litemall.

5

What could an attacker potentially exploit in CVE-2025-8974?

An attacker could exploit CVE-2025-8974 to manipulate JSON Web Token arguments, potentially leading to unauthorized access or data exposure.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203