Medium severity5.4NVD Advisory· Published Oct 8, 2026
CVE-2026-107801
CVE-2026-107801
Description
Jivejdon through 5.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to execute JavaScript by uploading attachments with an attacker-supplied Content-Type. Attackers can upload a file declared as text/html, which UploadShowAction serves inline, and share its link to run JavaScript on the application's origin for viewing users.
Affected products
1Patches
Vulnerability mechanics
References
4- github.com/banq/jivejdon/blob/ee67a65e65228644a71c8317d7e34deea50f95ef/src/main/java/com/jdon/jivejdon/domain/model/message/upload/UploadHelper.javanvd
- github.com/banq/jivejdon/blob/ee67a65e65228644a71c8317d7e34deea50f95ef/src/main/java/com/jdon/jivejdon/presentation/action/UploadShowAction.javanvd
- github.com/banq/jivejdon/issues/28nvd
- www.vulncheck.com/advisories/jivejdon-through-5.0-stored-xss-via-attachment-upload-content-typenvd
News mentions
0No linked articles in our index yet.