CVE-2026-107800
MEDIUM
NVD
CVSS Score
5.4
Severity
MEDIUM
Published
Oct 08, 2026
Vendor
unknown
Description
Jivejdon through 5.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject script into private short messages because receiveshortmessage.jsp renders unfiltered message bodies. Attackers can send a short message containing script, which ToolsUtil.convertURL() passes through unchanged, to execute code in the recipient's browser when opened.
References
- https://github.com/banq/jivejdon
- https://github.com/banq/jivejdon/blob/ee67a65e65228644a71c8317d7e34deea50f95ef/application/shortmessage/receiveshortmessage.jsp#L63
- https://github.com/banq/jivejdon/blob/ee67a65e65228644a71c8317d7e34deea50f95ef/src/main/java/com/jdon/jivejdon/presentation/form/ShortMessageForm.java#L89-L91
- https://github.com/banq/jivejdon/issues/28
- https://www.vulncheck.com/advisories/jivejdon-through-5.0-stored-xss-via-private-short-messages