{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-105572","assignerOrgId":"1af790b2-7ee1-4545-860a-a788eba489b5","state":"PUBLISHED","assignerShortName":"VulDB","dateReserved":"2026-10-05T16:09:37.161Z","datePublished":"2026-10-06T02:30:15.772Z","dateUpdated":"2026-10-06T13:18:52.036Z"},"containers":{"cna":{"providerMetadata":{"orgId":"1af790b2-7ee1-4545-860a-a788eba489b5","shortName":"VulDB","dateUpdated":"2026-10-06T02:30:15.772Z"},"title":"PickMall Lilishop Buyer Invoice List receipt authorization","problemTypes":[{"descriptions":[{"type":"CWE","cweId":"CWE-639","lang":"en","description":"Authorization Bypass"}]},{"descriptions":[{"type":"CWE","cweId":"CWE-285","lang":"en","description":"Improper Authorization"}]}],"affected":[{"vendor":"n/a","product":"PickMall Lilishop","versions":[{"version":"4.2.0","status":"affected"},{"version":"4.2.1","status":"affected"},{"version":"4.2.2","status":"affected"},{"version":"4.2.3","status":"affected"},{"version":"4.2.4","status":"affected"}],"cpes":["cpe:2.3:a:pickmall_lilishop:pickmall_lilishop:*:*:*:*:*:*:*:*"],"modules":["Buyer Invoice List"]}],"descriptions":[{"lang":"en","value":"A vulnerability has been found in PickMall Lilishop up to 4.2.4. This affects an unknown function of the file /buyer/trade/receipt of the component Buyer Invoice List. Such manipulation of the argument memberId leads to authorization bypass. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet."}],"metrics":[{"cvssV4_0":{"version":"4.0","baseScore":5.3,"vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P","baseSeverity":"MEDIUM"}},{"cvssV3_1":{"version":"3.1","baseScore":4.3,"vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:C","baseSeverity":"MEDIUM"}},{"cvssV3_0":{"version":"3.0","baseScore":4.3,"vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:C","baseSeverity":"MEDIUM"}},{"cvssV2_0":{"version":"2.0","baseScore":4,"vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N/E:POC/RL:ND/RC:C"}}],"timeline":[{"time":"2026-10-05T00:00:00.000Z","lang":"en","value":"Advisory disclosed"},{"time":"2026-10-05T02:00:00.000Z","lang":"en","value":"VulDB entry created"},{"time":"2026-10-05T18:14:46.000Z","lang":"en","value":"VulDB entry last update"}],"credits":[{"lang":"en","value":"cztang (VulDB User)","type":"reporter"},{"lang":"en","value":"VulDB CNA Team","type":"coordinator"}],"references":[{"url":"https://vuldb.com/vuln/413631","name":"VDB-413631 | PickMall Lilishop Buyer Invoice List receipt authorization","tags":["vdb-entry","technical-description"]},{"url":"https://vuldb.com/vuln/413631/cti","name":"VDB-413631 | CTI Indicators (IOB, IOC, IOA)","tags":["signature","permissions-required"]},{"url":"https://vuldb.com/cve/CVE-2026-105572","name":"CVE-2026-105572 | CVE Analysis and Report","tags":["third-party-advisory"]},{"url":"https://vuldb.com/submit/989312","name":"Submit #989312 | PickMall lilishop 4e6d563a4f0fa53880dd1420ce0904fc6e29f9e9 Missing Authorization","tags":["third-party-advisory"]},{"url":"https://github.com/lilishop/lilishop/issues/149","tags":["exploit","issue-tracking"]}],"x_generator":["VulDB PVTS v202610"]},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-10-06T13:18:41.374453Z","id":"CVE-2026-105572","options":[{"Exploitation":"poc"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-10-06T13:18:52.036Z"}}]}}