CVE-2026-105237

Summary

A vulnerability was detected in linlinjava litemall up to 1.8.0. This affects an unknown part of the file litemall-admin-api/src/main/java/org/linlinjava/litemall/admin/web/AdminAuthController.java of the component Login Endpoint. The manipulation results in improper restriction of excessive authentication attempts. The attack may be performed from remote. A high complexity level is associated with this attack. It is indicated that the exploitability is difficult. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

Affected Software

VendorProductVersion RangeStatus
linlinjavalitemall1.0affected
linlinjavalitemall1.1affected
linlinjavalitemall1.2affected
linlinjavalitemall1.3affected
linlinjavalitemall1.4affected
linlinjavalitemall1.5affected
linlinjavalitemall1.6affected
linlinjavalitemall1.7affected
linlinjavalitemall1.8.0affected

Weaknesses

  • CWE-307: Improper Restriction of Excessive Authentication Attempts
  • CWE-799: Improper Control of Interaction Frequency

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: poc
    • Automatable: no
    • Technical Impact: partial

References