CVE-2026-90570: linlinjava litemall Product Detail index.vue AdminGoodsService.validate cross site scripting
A vulnerability has been found in linlinjava litemall 1.4.0/1.5.0/1.6.0/1.7.0/1.8.0. This issue affects the function AdminGoodsService.validate of the file litemall-vue/src/views/items/detail/index.vue of the component Product Detail. Such manipulation of the argument detail leads to cross site scripting. The attack may be launched remotely. The project was informed of the problem early through an issue report but has not responded yet.
Affected Software
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
The attack can be launched remotely, but the CVSS vector indicates the attacker needs high privileges and requires user interaction. The vulnerable input is the detail argument handled by AdminGoodsService.validate.
Which litemall releases are identified as affected?
The reported affected versions are 1.4.0, 1.5.0, 1.6.0, 1.7.0, and 1.8.0.
Is a vendor response or fix identified?
The issue was reportedly disclosed to the project through an issue report, but the project had not responded at the time of publication. The available data does not identify a patch or fixed release.