CVE-2026-107799: fallo de gravedad media en banq jivejdon
Jivejdon through 5.0 Stored XSS via messageListBody.jsp Forum Message Rendering
Publicada el
10Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 5.1
probabilidad de explotación
—
explotación observada
noninguna fuente lo reporta
Jivejdon through 5.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject script by posting unsanitized forum message bodies. Message bodies are rendered by messageListBody.jsp with filter="false" and non-escaping default filters, executing script in the browser of every user viewing the thread.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N
Productos afectados
banq · jivejdonCVEs relacionadas — banq jivejdon
En el mismo producto, de las más peligrosas a las menos.
CVE-2026-107831MEDIUMJivejdon through 5.0 CSRF via GET-based Account and Thread ActionsEPSS —CVE-2026-107830MEDIUMJivejdon through commit ee67a65e Missing Rate Limiting via /account/smsVRAction SMS EndpointEPSS —CVE-2026-107829HIGHJivejdon through 5.0 Unsalted MD5 Password Storage via AccountDaoSqlEPSS —CVE-2026-107828MEDIUMJivejdon through 5.0 Predictable Passwords via Sina Weibo OAuth LoginEPSS —CVE-2026-107801MEDIUMJivejdon through 5.0 Stored XSS via Attachment Upload Content-TypeEPSS —CVE-2026-107800MEDIUMJivejdon through 5.0 Stored XSS via Private Short MessagesEPSS —
Referencias
https://github.com/banq/jivejdonhttps://github.com/banq/jivejdon/blob/ee67a65e65228644a71c8317d7e34deea50f95ef/application/thread/messageListBody.jsp#L136-L138https://github.com/banq/jivejdon/blob/ee67a65e65228644a71c8317d7e34deea50f95ef/src/main/java/com/jdon/jivejdon/domain/model/message/output/RenderingFilterManagerImp.java#L48-L49https://github.com/banq/jivejdon/issues/28https://www.vulncheck.com/advisories/jivejdon-through-5.0-stored-xss-via-messagelistbody-jsp-forum-message-rendering