CVE-2026-102366: mall4j through 4.0 Unrestricted File Upload in Admin File Endpoints
Published Sep 28, 2026
·Updated
mall4j through 4.0 contains an unrestricted file upload vulnerability in FileController endpoints that lack authorization checks and accept arbitrary file types without validation. Attackers with any authenticated token can upload HTML or SVG files that execute scripts in administrator browsers when accessed from the local storage path, resulting in stored cross-site scripting.
Affected Software
1 affected component
mall4j mall4j<=4.0
Event History
Sep 28, 2026
CVE Published
via MITRE·11:34 PM
Data Sourced
via MITRE·11:34 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Does exploitation require administrative privileges?
No. The affected endpoints lack authorization checks, and an attacker needs only any authenticated token to upload a malicious file.
2
Who is exposed to the resulting script execution?
Administrators are exposed when they access an uploaded HTML or SVG file through the local storage path. The uploaded content can then execute scripts in the administrator's browser.