Medium severity5.4NVD Advisory· Published Oct 8, 2026
CVE-2026-107800
CVE-2026-107800
Description
Jivejdon through 5.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject script into private short messages because receiveshortmessage.jsp renders unfiltered message bodies. Attackers can send a short message containing script, which ToolsUtil.convertURL() passes through unchanged, to execute code in the recipient's browser when opened.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
4- github.com/banq/jivejdon/blob/ee67a65e65228644a71c8317d7e34deea50f95ef/application/shortmessage/receiveshortmessage.jspnvd
- github.com/banq/jivejdon/blob/ee67a65e65228644a71c8317d7e34deea50f95ef/src/main/java/com/jdon/jivejdon/presentation/form/ShortMessageForm.javanvd
- github.com/banq/jivejdon/issues/28nvd
- www.vulncheck.com/advisories/jivejdon-through-5.0-stored-xss-via-private-short-messagesnvd
News mentions
0No linked articles in our index yet.