CVE-2025-8991: linlinjava litemall Business Logic express logic error
A vulnerability was identified in linlinjava litemall up to 1.8.0. Affected by this vulnerability is an unknown functionality of the file /admin/config/express of the component Business Logic Handler. The manipulation of the argument litemallexpressfreightmin leads to business logic errors. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8991?
CVE-2025-8991 has been identified as a critical vulnerability affecting linlinjava litemall up to version 1.8.0.
How do I fix CVE-2025-8991?
To mitigate CVE-2025-8991, upgrade linlinjava litemall to a version later than 1.8.0.
What component is affected by CVE-2025-8991?
CVE-2025-8991 affects the Business Logic Handler in the /admin/config/express file.
What types of attacks are possible due to CVE-2025-8991?
CVE-2025-8991 could potentially allow an attacker to manipulate business logic, leading to undesired actions within the application.
Is there a workaround for CVE-2025-8991?
There is no known workaround for CVE-2025-8991; the best course of action is to upgrade to a secure version of litemall.