An issue was discovered in litemall 0.9.0. Arbitrary file download is possible via ../ directory traversal in linlinjava/litemall/wx/web/WxStorageController.java in the litemall-wx-api component.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-18434.json"
"2026-04-11T11:39:40Z"
[
{
"digest": {
"length": 523.0,
"function_hash": "96696369334610697743408769115790146277"
},
"deprecated": false,
"signature_type": "Function",
"id": "CVE-2018-18434-1a0522a5",
"signature_version": "v1",
"source": "https://github.com/linlinjava/litemall/commit/49ab94d0052672d4fb642505d44b94a18abea332",
"target": {
"function": "download",
"file": "litemall-wx-api/src/main/java/org/linlinjava/litemall/wx/web/WxStorageController.java"
}
},
{
"digest": {
"length": 418.0,
"function_hash": "132900878510239747528676688137397217800"
},
"deprecated": false,
"signature_type": "Function",
"id": "CVE-2018-18434-8edbfcd8",
"signature_version": "v1",
"source": "https://github.com/linlinjava/litemall/commit/49ab94d0052672d4fb642505d44b94a18abea332",
"target": {
"function": "fetch",
"file": "litemall-wx-api/src/main/java/org/linlinjava/litemall/wx/web/WxStorageController.java"
}
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"61156782022435078365736256290978580660",
"150529089046009252282262868661007395271",
"216128168918769434751914760151925976629",
"298501460194646143563491339352291144462",
"275268899948578981886649810119026351895",
"210542490001809390165621182183818271848",
"130612534208309019081421269457475556251",
"113316971842657389825178937665474399592",
"162294934809481003654137574868485171720",
"302301535898693361968315070138888813095",
"304736416107486914007798968273995350263",
"150529089046009252282262868661007395271",
"216128168918769434751914760151925976629",
"298501460194646143563491339352291144462",
"275268899948578981886649810119026351895",
"210542490001809390165621182183818271848",
"130612534208309019081421269457475556251",
"113316971842657389825178937665474399592",
"187198733614269955402973279316509229044",
"156726085061399067872233506971015297061"
]
},
"deprecated": false,
"signature_type": "Line",
"id": "CVE-2018-18434-d4c1ddb1",
"signature_version": "v1",
"source": "https://github.com/linlinjava/litemall/commit/49ab94d0052672d4fb642505d44b94a18abea332",
"target": {
"file": "litemall-wx-api/src/main/java/org/linlinjava/litemall/wx/web/WxStorageController.java"
}
}
]