CVE-2026-107799mediumCWE-79

CVE-2026-107799: fallo de gravedad media en banq jivejdon

Jivejdon through 5.0 Stored XSS via messageListBody.jsp Forum Message Rendering

Publicada el

10Vexday Risk Score

Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.

ssvc Trackcvss 5.1
probabilidad de explotación
—
explotación observada
noninguna fuente lo reporta
Jivejdon through 5.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject script by posting unsanitized forum message bodies. Message bodies are rendered by messageListBody.jsp with filter="false" and non-escaping default filters, executing script in the browser of every user viewing the thread.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N
Productos afectados
banq · jivejdon