CVE-2026-105571
Received Received - Intake

Authorization Bypass in PickMall Lilishop Mobile Binding

Vulnerability report for CVE-2026-105571, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: VulDB

Description

A flaw has been found in PickMall Lilishop up to 4.2.4. The impacted element is an unknown function of the file /buyer/passport/member/bindMobile of the component Mobile Binding. This manipulation of the argument Username causes improper authorization. It is possible to initiate the attack remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 5 associated CPEs
Vendor Product Version / Range
n/a PickMall Lilishop 4.2.0
n/a PickMall Lilishop 4.2.1
n/a PickMall Lilishop 4.2.2
n/a PickMall Lilishop 4.2.3
n/a PickMall Lilishop 4.2.4

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-266 A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.
CWE-285 The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-105571 is an improper authorization flaw in PickMall Lilishop up to version 4.2.4. It allows unauthenticated attackers to take over user accounts by rebinding a victim's account to an attacker-controlled phone number using the /buyer/passport/member/bindMobile endpoint. The attack exploits a hard-coded SMS code '0' that bypasses verification checks.

Detection Guidance

Check for unauthorized mobile number rebinding attempts in logs for the /buyer/passport/member/bindMobile endpoint. Look for requests with the hard-coded SMS code '0' and attempts to change phone numbers without authentication.

Impact Analysis

If you use PickMall Lilishop, an attacker could hijack your account by rebinding it to their phone number. They could then access your personal data, order history, and perform actions on your behalf. The attack is remote and requires no authentication.

Compliance Impact

This vulnerability could lead to unauthorized access to personal data, violating GDPR's data protection principles and HIPAA's safeguards for protected health information. Organizations using affected versions may face compliance violations and legal consequences.

Mitigation Strategies

Disable the /buyer/passport/member/bindMobile endpoint if not critical. Implement proper authentication checks for mobile binding and SMS verification. Remove the hard-coded '0' code bypass in SmsUtilAliImplService.verifyCode. Update to a patched version if available.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105571. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart