CVE-2026-107801: Jivejdon through 5.0 Stored XSS via Attachment Upload Content-Type
Jivejdon through 5.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to execute JavaScript by uploading attachments with an attacker-supplied Content-Type. Attackers can upload a file declared as text/html, which UploadShowAction serves inline, and share its link to run JavaScript on the application's origin for viewing users.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue, and who is exposed to the resulting script execution?
An attacker needs an authenticated account with the ability to upload an attachment. Any user who opens a shared link to the uploaded attachment may execute the attacker-controlled JavaScript on the application's origin.
What attacker action triggers the vulnerability?
The attacker uploads an attachment while supplying a Content-Type of text/html, then shares the attachment link. UploadShowAction serves that file inline, allowing the browser to interpret it as HTML and run embedded JavaScript.
What can be done if an update is not immediately available?
Restrict attachment-upload capability to trusted users and prevent uploaded files from being declared or served as text/html. Avoid opening links to untrusted uploaded attachments until the issue is remediated.