Sceawere
Vulnerability Detail
CVE-2026-102366UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Unrestricted File Upload XSS Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.4
- Creation Date
- 7h ago
- Vendor
- gz-yami
- Product
- mall4j
- Attack Type
- Unrestricted Upload of File with Dangerous Type
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:N
- Attack Complexity
- HIGH
Narrative and Response
Description
mall4j through 4.0 contains an unrestricted file upload vulnerability in FileController endpoints that lack authorization checks and accept arbitrary file types without validation. Attackers with any authenticated token can upload HTML or SVG files that execute scripts in administrator browsers when accessed from the local storage path, resulting in stored cross-site scripting.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.4",
"pubDate": "2026-09-29T00:17:03.917Z",
"pubdate": "2026-09-29T00:17:03.917Z",
"executiveSummary": "The mall4j product, specifically up to version 4.0, suffers from an unrestricted file upload vulnerability located within the FileController component. This security flaw stems from a critical absence of authorization checks and a complete lack of server-side validation for file types during the upload process.\nThe vulnerability enables authenticated users, regardless of their privilege level, to upload malicious artifacts such as HTML or SVG files to the application's storage path. When these files are accessed by an administrator or another user, the browser interprets the embedded scripts, facilitating a Stored Cross-Site Scripting (XSS) attack.\nThe risk implications are significant, as successful exploitation allows for the execution of arbitrary JavaScript within the context of the victim's session. This may lead to session hijacking, unauthorized actions on behalf of the administrator, or further compromise of the administrative interface. The attack requires a valid authentication token but does not require elevated privileges, making it a highly accessible vector for malicious actors within the system.",
"technicalDetails": "The root cause of this vulnerability is the implementation of the FileController within mall4j 4.0 and earlier, which fails to enforce mandatory authorization controls or implement file signature/MIME-type validation. The application accepts multipart file uploads and writes them directly to the local storage filesystem without sanitizing the filename or inspecting the file content.\nThe attack flow begins with an attacker obtaining a valid authentication token, which is a prerequisite for accessing the vulnerable endpoints. The attacker sends a crafted POST request to the FileController, incorporating a malicious payload—typically an HTML or SVG document containing an embedded <script> tag or event handler (e.g., onload). Because the server lacks blacklisting or whitelisting mechanisms for file extensions, the application saves the malicious file to the publicly accessible storage path.\nOnce the file is uploaded, the attacker obtains the direct URL to the stored asset. The XSS payload remains dormant until the target victim, such as a high-privileged administrator, navigates to the file path. When the browser loads the malicious document, the embedded JavaScript executes in the security context of the origin where the file is hosted.\nThe impact of this stored XSS is substantial. By executing scripts in the administrator's browser, the attacker can perform actions such as stealing session cookies, exfiltrating sensitive administrative data, modifying application configurations, or performing unauthorized API requests using the victim's credentials. The lack of validation on the upload endpoint ensures that the attacker can bypass any client-side restrictions, and because the files are stored locally and served directly, the application becomes a vehicle for delivering malicious payloads to other authenticated users."
}