CVE-2026-107800: falha de média gravidade em banq jivejdon
Jivejdon through 5.0 Stored XSS via Private Short Messages
Publicada em
10Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackcvss 5.1
probabilidade de exploração
—
exploração observada
nãonenhuma fonte reporta
Jivejdon through 5.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject script into private short messages because receiveshortmessage.jsp renders unfiltered message bodies. Attackers can send a short message containing script, which ToolsUtil.convertURL() passes through unchanged, to execute code in the recipient's browser when opened.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N
Produtos afetados
banq · jivejdonCVEs relacionadas — banq jivejdon
No mesmo produto, das mais perigosas para as menos.
CVE-2026-107831MEDIUMJivejdon through 5.0 CSRF via GET-based Account and Thread ActionsEPSS —CVE-2026-107830MEDIUMJivejdon through commit ee67a65e Missing Rate Limiting via /account/smsVRAction SMS EndpointEPSS —CVE-2026-107829HIGHJivejdon through 5.0 Unsalted MD5 Password Storage via AccountDaoSqlEPSS —CVE-2026-107828MEDIUMJivejdon through 5.0 Predictable Passwords via Sina Weibo OAuth LoginEPSS —CVE-2026-107801MEDIUMJivejdon through 5.0 Stored XSS via Attachment Upload Content-TypeEPSS —CVE-2026-107799MEDIUMJivejdon through 5.0 Stored XSS via messageListBody.jsp Forum Message RenderingEPSS —
Referências
https://github.com/banq/jivejdonhttps://github.com/banq/jivejdon/blob/ee67a65e65228644a71c8317d7e34deea50f95ef/application/shortmessage/receiveshortmessage.jsp#L63https://github.com/banq/jivejdon/blob/ee67a65e65228644a71c8317d7e34deea50f95ef/src/main/java/com/jdon/jivejdon/presentation/form/ShortMessageForm.java#L89-L91https://github.com/banq/jivejdon/issues/28https://www.vulncheck.com/advisories/jivejdon-through-5.0-stored-xss-via-private-short-messages