CVE-2026-107797: Jivejdon through 5.0 Reflected XSS via postThread.jsp to and tag Parameters
Jivejdon through 5.0 contains a reflected cross-site scripting vulnerability in application/message/postThread.jsp that allows attackers to inject script via the to and tag parameters. Attackers can send crafted links to authenticated users, breaking out of unencoded inline JavaScript string literals to execute arbitrary JavaScript in the victim's session.
Affected Software
Event History
Frequently Asked Questions
Who can be targeted by this vulnerability?
Authenticated Jivejdon users who can be induced to open an attacker-crafted link to application/message/postThread.jsp can be targeted. The injected JavaScript executes in the targeted user's session.
What does an attacker need to exploit it?
The attacker needs to craft a link that supplies malicious content through the to or tag parameter and convince an authenticated user to follow it. No attacker authentication is indicated.
Which versions are affected?
Jivejdon through version 5.0 is affected.