← Back to CVE List
CVE-2026-90570NVD
Description
A vulnerability has been found in linlinjava litemall 1.4.0/1.5.0/1.6.0/1.7.0/1.8.0. This issue affects the function AdminGoodsService.validate of the file litemall-vue/src/views/items/detail/index.vue of the component Product Detail. Such manipulation of the argument detail leads to cross site scripting. The attack may be launched remotely. The project was informed of the problem early through an issue report but has not responded yet.
CVSS Base Metrics
CVSS v3 (3.1)
LOW 2.4
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N/E:X/RL:X/RC:R
CVSS v4 (4.0)
MEDIUM 4.8
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X
Affected & Patched Versions
| Product | Affected Versions | Patched Version |
|---|---|---|
| linlinjava litemall | 1.4.0, 1.5.0, 1.6.0, 1.7.0, 1.8.0 | N/A |