CVE-2026-105180: Jeebase UserService info updateUser dynamically-determined object attributes
A vulnerability was determined in Jeebase 0.0.1. This vulnerability affects the function updateUser of the file /user/update/info of the component UserService. Executing a manipulation of the argument user/tempUser can lead to dynamically-determined object attributes. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.
Affected Software
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The attacker needs low-level privileges and can exploit the issue remotely. No user interaction is required.
How likely is active exploitation?
Public exploit details have been disclosed and may be used. The exploitability assessment is rated as proof-of-concept.
Is a vendor fix available?
The provided information does not identify a fix. The project was notified through an issue report but had not responded at the time of disclosure.