在 PickMall Lilishop(版本高达 4.2.4)中发现了一个安全缺陷。受影响的是“手机号绑定”组件中 /buyer/passport/member/bindMobile 文件的一个未知函数。对参数 Username 的操控导致了不正确的授权控制。攻击者可以远程发起攻击。该漏洞的利用代码已经公开,可以被利用。该项目已通过问题报告较早地获知此问题,但尚未作出回应。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | PickMall Lilishop | 4.2.0 |
cpe:2.3:a:pickmall_lilishop:pickmall_lilishop:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-105707 | 5.3 MEDIUM | uptrace user_handler.go Login information exposure |
| CVE-2026-105708 | 4.3 MEDIUM | imgproxy SVG svg.go sanitizeElement cross site scripting |
| CVE-2026-105572 | 4.3 MEDIUM | PickMall Lilishop Buyer Invoice List receipt authorization |
No comments yet