A security vulnerability has been detected in linlinjava litemall up to 1.8.0. Affected by this vulnerability is the function backup/load of the file litemall-db/src/main/java/org/linlinjava/litemall/db/util/DbUtil.java of the component Database Setting Handler. The manipulation of the argument db/password leads to argument injection. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Metrics
Affected Vendors & Products
References
History
Mon, 18 May 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security vulnerability has been detected in linlinjava litemall up to 1.8.0. Affected by this vulnerability is the function backup/load of the file litemall-db/src/main/java/org/linlinjava/litemall/db/util/DbUtil.java of the component Database Setting Handler. The manipulation of the argument db/password leads to argument injection. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | linlinjava litemall Database Setting DbUtil.java load argument injection | |
| First Time appeared |
Linlinjava
Linlinjava litemall |
|
| Weaknesses | CWE-74 CWE-88 |
|
| CPEs | cpe:2.3:a:linlinjava:litemall:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Linlinjava
Linlinjava litemall |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2026-05-18T00:00:13.854Z
Updated: 2026-05-18T00:00:13.854Z
Reserved: 2026-05-17T09:36:19.258Z
Link: CVE-2026-8773
No data.
Status : Received
Published: 2026-05-18T00:16:37.893
Modified: 2026-05-18T00:16:37.893
Link: CVE-2026-8773
No data.
ReportizFlow