GHSA-rq35-wp93-7v6gMediumCVSS 5.4
Jivejdon through 5.0 contains a stored cross-site scripting vulnerability that allows...
🔗 CVE IDs covered (1)
📋 Description
Jivejdon through 5.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject script into private short messages because receiveshortmessage.jsp renders unfiltered message bodies. Attackers can send a short message containing script, which ToolsUtil.convertURL() passes through unchanged, to execute code in the recipient's browser when opened.
🔗 References (7)
- https://nvd.nist.gov/vuln/detail/CVE-2026-107800
- https://github.com/banq/jivejdon/issues/28
- https://github.com/banq/jivejdon
- https://github.com/banq/jivejdon/blob/ee67a65e65228644a71c8317d7e34deea50f95ef/application/shortmessage/receiveshortmessage.jsp#L63
- https://github.com/banq/jivejdon/blob/ee67a65e65228644a71c8317d7e34deea50f95ef/src/main/java/com/jdon/jivejdon/presentation/form/ShortMessageForm.java#L89-L91
- https://www.vulncheck.com/advisories/jivejdon-through-5.0-stored-xss-via-private-short-messages
- https://github.com/advisories/GHSA-rq35-wp93-7v6g