SQL injection vulnerability in linlinjava litemall v.1.8.0 allows a remote attacker to obtain sensitive information via the nickname, consignee, orderSN, orderStatusArray parameters of the AdminOrdercontroller.java component.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 15 Sep 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:linlinjava:litemall:*:*:*:*:*:*:*:* |
Wed, 28 Aug 2024 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-89 | |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-28T15:48:52.290Z
Reserved: 2024-01-25T00:00:00
Link: CVE-2024-24323
Updated: 2024-08-01T23:19:52.107Z
Status : Analyzed
Published: 2024-02-27T17:15:12.103
Modified: 2025-09-15T17:09:47.700
Link: CVE-2024-24323
No data.
OpenCVE Enrichment
Updated: 2025-07-12T22:31:10Z
Weaknesses