CVE-2026-107792: falha de média gravidade em banq jivejdon
Jivejdon through commit ee67a65e Missing Authorization via /message/threadToForum/save Thread Move
Publicada em
10Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackcvss 5.3
probabilidade de exploração
—
exploração observada
nãonenhuma fonte reporta
Jivejdon from commit d58a36b0 through commit ee67a65e contains a missing authorization vulnerability in UpdateThreadToForumAction that allows authenticated users to move other users' threads. Attackers can send crafted threadId and forumId values to /message/threadToForum/save to relocate any reply-less thread into an arbitrary forum.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Produtos afetados
banq · jivejdonCVEs relacionadas — banq jivejdon
No mesmo produto, das mais perigosas para as menos.
CVE-2026-107831MEDIUMJivejdon through 5.0 CSRF via GET-based Account and Thread ActionsEPSS —CVE-2026-107830MEDIUMJivejdon through commit ee67a65e Missing Rate Limiting via /account/smsVRAction SMS EndpointEPSS —CVE-2026-107829HIGHJivejdon through 5.0 Unsalted MD5 Password Storage via AccountDaoSqlEPSS —CVE-2026-107828MEDIUMJivejdon through 5.0 Predictable Passwords via Sina Weibo OAuth LoginEPSS —CVE-2026-107801MEDIUMJivejdon through 5.0 Stored XSS via Attachment Upload Content-TypeEPSS —CVE-2026-107800MEDIUMJivejdon through 5.0 Stored XSS via Private Short MessagesEPSS —
Referências
https://github.com/banq/jivejdonhttps://github.com/banq/jivejdon/blob/ee67a65e65228644a71c8317d7e34deea50f95ef/application/WEB-INF/struts-config-message.xml#L136-L140https://github.com/banq/jivejdon/blob/ee67a65e65228644a71c8317d7e34deea50f95ef/src/main/java/com/jdon/jivejdon/presentation/action/message/UpdateThreadToForumAction.java#L25-L62https://github.com/banq/jivejdon/issues/28https://www.vulncheck.com/advisories/jivejdon-through-commit-ee67a65e-missing-authorization-via-message-threadtoforum-save-thread-move