CVE-2026-105571: PickMall Lilishop Mobile Binding bindMobile improper authorization
A flaw has been found in PickMall Lilishop up to 4.2.4. The impacted element is an unknown function of the file /buyer/passport/member/bindMobile of the component Mobile Binding. This manipulation of the argument Username causes improper authorization. It is possible to initiate the attack remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Affected Software
Event History
Frequently Asked Questions
Which deployments are affected?
PickMall Lilishop versions up to 4.2.4 are affected in the Mobile Binding component, specifically the /buyer/passport/member/bindMobile endpoint.
What does an attacker need to exploit this issue?
The attack can be initiated remotely and requires no privileges or user interaction according to the supplied severity vector. Exploitation involves manipulating the Username argument.
Is exploitation publicly available?
Yes. An exploit has been published and may be used.
What should teams do if they cannot patch immediately?
The provided information does not identify an available patch or a specific workaround. Prioritize restricting access to the affected mobile-binding endpoint where operationally possible and investigate requests that manipulate the Username argument.