📦 Tmall Demo

by Project Team

🔍 What is Tmall Demo?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-40554

HIGH CVSS 7.5 Jul 15, 2024

An access control vulnerability in Tmall_demo v2024.07.03 allows attackers to bypass authentication mechanisms and access sensitive information. This affects all systems running the vulnerable version...

CVE-2024-40560

HIGH CVSS 7.3 Jul 15, 2024

This SQL injection vulnerability in Tmall_demo allows attackers to execute arbitrary SQL commands through user input. It affects all systems running Tmall_demo versions before v2024.07.03. Attackers c...

CVE-2025-5132

MEDIUM CVSS 4.3 May 24, 2025

This CSRF vulnerability in Tmall Demo allows attackers to trick authenticated administrators into performing unintended logout actions via malicious requests. It affects all versions up to 20250505 wh...

CVE-2025-5130

MEDIUM CVSS 4.7 May 24, 2025

This critical vulnerability in Tmall Demo allows remote attackers to upload arbitrary files without restrictions via the uploadProductImage function. This affects all versions up to May 5, 2025. Attac...

CVE-2025-1843

MEDIUM CVSS 6.3 Mar 3, 2025

This critical SQL injection vulnerability in Mini-Tmall allows remote attackers to execute arbitrary SQL commands by manipulating the 'orderBy' parameter in the ProductMapper.java file. This can lead ...

CVE-2024-40553

MEDIUM CVSS 4.9 Jul 15, 2024

Tmall_demo v2024.07.03 contains an unrestricted file upload vulnerability in the uploadUserHeadImage component, allowing attackers to upload malicious files to the server. This affects all users runni...