CVE-2025-8965 | linlinjava litemall up to 1.8.0 Endpoint AdminStorageController.java create File unrestricted upload
A vulnerability classified as critical was found in linlinjava litemall up to 1.8.0. This vulnerability affects the function create of the file litemall-admin-api/src/main/java/org/linlinjava/litemall/admin/web/AdminStorageController.java of the component Endpoint. The manipulation of the argument File leads to unrestricted upload.
This vulnerability was named CVE-2025-8965. The attack can be initiated remotely. Furthermore, there is an exploit available.