<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:pickmall:lilishop:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3apickmalllilishop/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 06 Oct 2026 02:52:02 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3apickmalllilishop/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Improper Authorization Vulnerability in PickMall Lilishop</title><link>https://feed.craftedsignal.io/briefs/2026-10-lilishop-auth-bypass/</link><pubDate>Tue, 06 Oct 2026 02:52:02 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-lilishop-auth-bypass/</guid><description>PickMall Lilishop up to version 4.2.4 contains an improper authorization vulnerability in the Mobile Binding component, allowing remote attackers to manipulate the Username argument to bypass authorization controls.</description><content:encoded><![CDATA[<p>A security vulnerability (CVE-2026-105571) exists in the PickMall Lilishop e-commerce platform, affecting all versions up to and including 4.2.4. The flaw resides within the Mobile Binding component, specifically triggered through the /buyer/passport/member/bindMobile endpoint. By manipulating the Username argument, an unauthenticated or unauthorized remote attacker can successfully bypass intended authorization checks. The vulnerability has been publicly disclosed and a proof-of-concept exploit exists, increasing the risk of unauthorized account manipulation or account takeover. The project maintainers were notified of the issue but have not yet provided a resolution or patch. Defenders should treat this as a high-priority risk for internet-facing Lilishop instances, as the exploit is remote and does not require pre-existing authentication.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability allows unauthorized manipulation of member mobile bindings within the Lilishop platform. Successful exploitation grants an attacker the ability to associate arbitrary mobile numbers with existing accounts or potentially hijack access to accounts, resulting in full account compromise. Given the platform's role in e-commerce, this could lead to the unauthorized access of sensitive user data, fraudulent transactions, or significant disruption to business operations for organizations relying on this software.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Monitor web server logs for HTTP requests directed to the /buyer/passport/member/bindMobile endpoint.</li>
<li>Implement stricter input validation or temporary blocking of the affected endpoint at the Web Application Firewall (WAF) level if not business-critical.</li>
<li>Since no patch is currently available, perform continuous monitoring of user account binding activity for anomalous or unauthorized changes.</li>
</ul>
]]></content:encoded><category domain="severity">medium</category><category domain="type">advisory</category><category>web-application-vulnerability</category><category>auth-bypass</category></item></channel></rss>