CVE-2026-102366 PUBLISHED

mall4j through 4.0 Unrestricted File Upload in Admin File Endpoints

Assigner: VulnCheck
Reserved: 28.09.2026 Published: 28.09.2026 Updated: 29.09.2026

mall4j through 4.0 contains an unrestricted file upload vulnerability in FileController endpoints that lack authorization checks and accept arbitrary file types without validation. Attackers with any authenticated token can upload HTML or SVG files that execute scripts in administrator browsers when accessed from the local storage path, resulting in stored cross-site scripting.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
CVSS Score: 2.1

Product Status

Vendor gz-yami
Product mall4j
Versions Default: unaffected
  • affected from 0 to 4.0 (incl.)

Credits

  • Mingsheng Lin finder

References

Problem Types

  • Unrestricted Upload of File with Dangerous Type CWE