A vulnerability was detected in linlinjava litemall up to 1.8.0. This affects an unknown part of the file litemall-admin-api/src/main/java/org/linlinjava/litemall/admin/web/AdminAuthController.java of the component Login Endpoint. The manipulation results in improper restriction of excessive authentication attempts. The attack may be performed from remote. A high complexity level is associated with this a [truncated]
A low-severity argument injection vulnerability exists in the linlinjava litemall project, affecting versions up to 1.8.0. The vulnerability resides in the `backup/load` function within `DbUtil.java`, where improper handling of the `db/password` parameter allows remote attackers to inject arguments. The CVSS 4.0 score of 2.0 reflects limited impact due to high privileges required for exploitation. The ven [truncated]