在 PickMall Lilishop 4.2.4 及更早版本中存在一个漏洞。该漏洞影响“买家发票列表”(Buyer Invoice List)组件中 文件的某个未知函数。通过对参数 的操纵,可导致权限绕过(authorization bypass)。攻击者能够远程发起攻击。目前该漏洞的利用方法已公开,可能被恶意利用。该项目已通过问题报告较早得知此漏洞,但至今尚未作出回应。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | PickMall Lilishop | 4.2.0 |
cpe:2.3:a:pickmall_lilishop:pickmall_lilishop:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-105571 | 7.3 HIGH | PickMall Lilishop Mobile Binding bindMobile improper authorization |
| CVE-2026-105707 | 5.3 MEDIUM | uptrace user_handler.go Login information exposure |
| CVE-2026-105708 | 4.3 MEDIUM | imgproxy SVG svg.go sanitizeElement cross site scripting |
No comments yet