GHSA-f6hh-58p2-7rx3HighCVSS 8.8

The storage endpoint /storage/upload of cjbi admin3 v3.0.0 are missing permission checks. /Any...

Published
August 28, 2026
Last Modified
August 28, 2026

🔗 CVE IDs covered (1)

📋 Description

The storage endpoint /storage/upload of cjbi admin3 v3.0.0 are missing permission checks. /Any logged-in user can upload arbitrary files, and any anonymous attacker can download them.

🔗 References (3)