---
id: CVE-2026-105572
title: A vulnerability has been found in PickMall Lilishop up to 4.2.4
summary: >-
  A vulnerability has been found in PickMall Lilishop up to 4.2.4. This affects
  an unknown function of the file /buyer/trade/receipt of the component Buyer
  Invoice List. Such manipulation of the argument memberId leads to
  authorization byp…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-285
  - CWE-639
product: PickMall Lilishop
affected:
  - pickmall_lilishop 4.2.0
  - pickmall_lilishop 4.2.1
  - pickmall_lilishop 4.2.2
  - pickmall_lilishop 4.2.3
  - pickmall_lilishop 4.2.4
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T03:17:00.827'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-105572'
references:
  - url: 'https://github.com/lilishop/lilishop/issues/149'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-105572'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/989312'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/413631'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/413631/cti'
    label: cna@vuldb.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-06T05:47:09.319Z'
---

## Overview

A vulnerability has been found in PickMall Lilishop up to 4.2.4. This affects an unknown function of the file /buyer/trade/receipt of the component Buyer Invoice List. Such manipulation of the argument memberId leads to authorization bypass. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
