CVE-2026-102366
Received Received - Intake

Unrestricted File Upload in mall4j Leads to Stored XSS

Vulnerability report for CVE-2026-102366, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: VulnCheck

Description

mall4j through 4.0 contains an unrestricted file upload vulnerability in FileController endpoints that lack authorization checks and accept arbitrary file types without validation. Attackers with any authenticated token can upload HTML or SVG files that execute scripts in administrator browsers when accessed from the local storage path, resulting in stored cross-site scripting.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
mall4j mall4j From 3.0 (inc) to 4.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-434 The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-102366 is an unrestricted file upload vulnerability in the mall4j e-commerce platform (versions 4.0 and earlier). It affects admin file-upload endpoints that lack authorization checks. Attackers with any authenticated token can upload arbitrary files, including HTML or SVG files, without validation. When stored locally, these files execute scripts in administrator browsers, enabling stored cross-site scripting (XSS) attacks.

Detection Guidance

To detect this vulnerability, check if your mall4j instance has endpoints POST /admin/file/upload/element or POST /admin/file/upload/tinymceEditor without authorization checks. Inspect FileController.java for missing @PreAuthorize annotations. Verify if AttachFileServiceImpl#uploadFile allows arbitrary file uploads without extension or content-type validation.

Impact Analysis

This vulnerability allows attackers to upload malicious files that execute scripts in admin browsers. This could lead to session hijacking, unauthorized access to admin accounts, or further compromise of the system. Even basic authenticated tokens (like shopper accounts) can be exploited to upload files.

Compliance Impact

This vulnerability could violate compliance requirements by enabling unauthorized access to sensitive admin data, potentially leading to data breaches. GDPR and HIPAA require protecting personal and health data, respectively. A successful XSS attack could expose such data, resulting in regulatory penalties or legal consequences.

Mitigation Strategies

Immediately upgrade mall4j to a version beyond 4.0. Add @PreAuthorize annotations to FileController endpoints to enforce admin authorization. Implement strict file extension whitelists and content-type validation in AttachFileServiceImpl#uploadFile. Disable local storage uploads if not required or restrict access to uploaded files.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102366. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart