yshopmall <=3.3 is vulnerable to Cross Site Scripting (XSS). The file upload endpoint /api/upload of the system lacks file type validation. Attackers can upload files of any type, including HTML, JSP, and other executable files.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-09 22:18
Updated : 2026-09-14 13:18
NVD link : CVE-2026-75308
Mitre link : CVE-2026-75308
CVE.ORG link : CVE-2026-75308
JSON object : View
Products Affected
No product.
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
