Sceawere

Vulnerability Detail

CVE-2026-105237UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Litemall Improper Authentication Rate Limiting

Vulnerability Metadata

Severity
Low
Score / CVSS
3.7
Creation Date
12h ago
Vendor
linlinjava
Product
litemall
Attack Type
Improper Restriction of Excessive Authentication Attempts
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
HIGH

Narrative and Response

Description

A vulnerability was detected in linlinjava litemall up to 1.8.0. This affects an unknown part of the file litemall-admin-api/src/main/java/org/linlinjava/litemall/admin/web/AdminAuthController.java of the component Login Endpoint. The manipulation results in improper restriction of excessive authentication attempts. The attack may be performed from remote. A high complexity level is associated with this attack. It is indicated that the exploitability is difficult. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "3.7",
  "pubDate": "2026-10-05T06:16:57.997Z",
  "pubdate": "2026-10-05T06:16:57.997Z",
  "executiveSummary": "A vulnerability has been identified in linlinjava litemall up to version 1.8.0, specifically located within the Login Endpoint handled by AdminAuthController.java.\nThe vulnerability is classified as an improper restriction of excessive authentication attempts, effectively manifesting as a lack of robust brute-force or credential-stuffing protection mechanisms.\nThe flaw permits remote attackers to perform an unlimited series of authentication requests against the administrative interface, increasing the likelihood of unauthorized account access via credential brute-forcing.\nWhile the vulnerability is categorized as having a high complexity level and being difficult to exploit, the availability of public exploit information elevates the risk profile for organizations utilizing this software.\nSuccessful exploitation requires the attacker to have network access to the administrative login endpoint, enabling them to bypass standard account lockout or rate-limiting thresholds that are typically expected in secure authentication systems.\nThe vendor has been notified of the vulnerability but has not yet provided a response or a patch to remediate the identified oversight in the authentication logic.",
  "technicalDetails": "The vulnerability resides in the authentication logic implemented within litemall-admin-api/src/main/java/org/linlinjava/litemall/admin/web/AdminAuthController.java. The root cause is the absence of a server-side state mechanism or request throttling policy to constrain the frequency and volume of login attempts initiated by a single remote entity or IP address.\nIn a secure authentication workflow, the system should implement countermeasures such as Exponential Backoff, CAPTCHA integration after failed attempts, or temporary account lockouts. The current implementation in Litemall versions 1.8.0 and below lacks these controls, allowing the endpoint to process consecutive authentication requests without meaningful delay or termination.\nThe attack flow involves an attacker targeting the login API endpoint with a continuous stream of authentication payloads. Because the AdminAuthController does not validate the frequency of these attempts, an attacker can script automated credential-stuffing attacks using lists of leaked credentials or dictionary-based password cracking tools. By bypassing common rate-limiting controls, the attacker significantly improves the probability of discovering valid credentials for administrative accounts.\nExploitation is categorized as remote, requiring only connectivity to the admin-api service. Although the vulnerability is noted as high complexity, this likely refers to the necessity of overcoming potential application-level hurdles or WAF configurations that might be present in specific deployment environments. However, the lack of intrinsic, code-level rate limiting in the controller itself provides the fundamental building block for a successful brute-force campaign.\nThe post-exploitation impact is critical, as successful credential discovery allows for unauthorized administrative access to the Litemall instance. Once authenticated, an attacker may leverage the administrative privileges to gain full control over the e-commerce platform, modify sensitive configuration data, access customer records, or perform remote code execution if the administrative interface includes features that interact with system-level commands or file uploads.\nThe vulnerability remains exploitable in all identified versions up to 1.8.0, as the backend code continues to accept requests without enforcing authentication attempt limitations. The public disclosure of the exploit code exacerbates the exposure, as the barrier to entry for potential adversaries is significantly lowered."
}
CVE-2026-105237: Litemall Improper Authentication Rate Limiting (LOW Severity, CVSS: 3.7) | Sceawere