CVE-2026-8773 | linlinjava litemall up to 1.8.0 Database Setting DbUtil.java backup/load db/password argument injection
A vulnerability was found in linlinjava litemall up to 1.8.0. It has been classified as critical. Affected by this vulnerability is the function backup/load of the file litemall-db/src/main/java/org/linlinjava/litemall/db/util/DbUtil.java of the component Database Setting Handler. The manipulation of the argument db/password leads to argument injection.
This vulnerability is uniquely identified as CVE-2026-8773. The attack is possible to be carried out remotely. Moreover, an exploit is present.
The vendor was contacted early about this disclosure but did not respond in any way.