CVE-2025-8974 Information
Description
A vulnerability was determined in linlinjava litemall up to 1.8.0. Affected by this issue is some unknown functionality of the file litemall-wx-api/src/main/java/org/linlinjava/litemall/wx/util/JwtHelper.java of the component JSON Web Token Handler. The manipulation of the argument SECRET with the input X-Litemall-Token leads to hard-coded credentials. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used.
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
Reference
https://github.com/linlinjava/litemall/issues/568 https://github.com/linlinjava/litemall/issues/568#issue-3289860066 https://vuldb.com/?ctiid.319970 https://vuldb.com/?id.319970 https://vuldb.com/?submit.628233
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
NONE
Availability Impact
LOW
Base Score
NONE
Base Severity
3.7
Related CNNVD
CNNVD-202508-1727 (Published: 2025-08-14)
Share on: