Loading market data...
← Back to CVE feed

CVE-2026-102366

MEDIUM CVSS 4.4 View on NVD ↗

Description

mall4j through 4.0 contains an unrestricted file upload vulnerability in FileController endpoints that lack authorization checks and accept arbitrary file types without validation. Attackers with any authenticated token can upload HTML or SVG files that execute scripts in administrator browsers when accessed from the local storage path, resulting in stored cross-site scripting.

CVSS Vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:N
Published: Sep 29, 2026 00:17 UTC Modified: Sep 29, 2026 11:16 UTC