A vulnerability was identified in linlinjava litemall up to 1.8.0. Affected by this vulnerability is an unknown functionality of the file /admin/config/express of the component Business Logic Handler. The manipulation of the argument litemall_express_freight_min leads to business logic errors. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Weaknesses in this category identify some of the underlying problems that commonly allow attackers to manipulate the business logic of an application. Errors in business logic can be devastating to an entire application. They can be difficult to find automatically, since they typically involve legitimate use of the application's functionality. However, many business logic errors can exhibit patterns that are similar to well-understood implementation and design weaknesses.
Link | Tags |
---|---|
https://vuldb.com/?id.319987 | vdb entry technical description |
https://vuldb.com/?ctiid.319987 | signature permissions required |
https://vuldb.com/?submit.628764 | third party advisory |
https://github.com/linlinjava/litemall/issues/566 | issue tracking |
https://github.com/linlinjava/litemall/issues/566#issue-3267858791 | exploit issue tracking |