Metrics
Affected Vendors & Products
Fri, 15 Aug 2025 08:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Linlinjava
Linlinjava litemall |
|
Vendors & Products |
Linlinjava
Linlinjava litemall |
Thu, 14 Aug 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 14 Aug 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability was determined in linlinjava litemall up to 1.8.0. Affected by this issue is some unknown functionality of the file litemall-wx-api/src/main/java/org/linlinjava/litemall/wx/util/JwtHelper.java of the component JSON Web Token Handler. The manipulation of the argument SECRET with the input X-Litemall-Token leads to hard-coded credentials. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. | |
Title | linlinjava litemall JSON Web Token JwtHelper.java hard-coded credentials | |
Weaknesses | CWE-259 CWE-798 |
|
References |
| |
Metrics |
cvssV2_0
|

Status: PUBLISHED
Assigner: VulDB
Published: 2025-08-14T18:02:08.547Z
Updated: 2025-08-14T19:17:47.420Z
Reserved: 2025-08-13T16:26:27.842Z
Link: CVE-2025-8974

Updated: 2025-08-14T18:34:57.851Z

Status : Awaiting Analysis
Published: 2025-08-14T18:15:32.070
Modified: 2025-08-15T13:12:51.217
Link: CVE-2025-8974

No data.