GHSA-3x3v-g28r-qvqhMediumCVSS 5.4
Jivejdon through 5.0 contains a stored cross-site scripting vulnerability that allows...
🔗 CVE IDs covered (1)
📋 Description
Jivejdon through 5.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject script by posting unsanitized forum message bodies. Message bodies are rendered by messageListBody.jsp with filter="false" and non-escaping default filters, executing script in the browser of every user viewing the thread.
🔗 References (7)
- https://nvd.nist.gov/vuln/detail/CVE-2026-107799
- https://github.com/banq/jivejdon/issues/28
- https://github.com/banq/jivejdon
- https://github.com/banq/jivejdon/blob/ee67a65e65228644a71c8317d7e34deea50f95ef/application/thread/messageListBody.jsp#L136-L138
- https://github.com/banq/jivejdon/blob/ee67a65e65228644a71c8317d7e34deea50f95ef/src/main/java/com/jdon/jivejdon/domain/model/message/output/RenderingFilterManagerImp.java#L48-L49
- https://www.vulncheck.com/advisories/jivejdon-through-5.0-stored-xss-via-messagelistbody-jsp-forum-message-rendering
- https://github.com/advisories/GHSA-3x3v-g28r-qvqh