CVE-2026-107831: Jivejdon through 5.0 CSRF via GET-based Account and Thread Actions
Jivejdon through 5.0 contains a cross-site request forgery vulnerability that allows remote attackers to perform state-changing actions by abusing GET endpoints lacking anti-CSRF tokens. Attackers can lure authenticated users to crafted links targeting /account/protected/delAll, /account/protected/sub/delSub, or /message/updateAction to delete private messages and subscriptions or rename threads.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
Authenticated Jivejdon users are exposed if they can be induced to visit an attacker-controlled crafted link. The issue affects Jivejdon through version 5.0.
What can an attacker do through this vulnerability?
An attacker can cause state-changing requests to delete private messages, delete subscriptions, or rename threads. The attacker does not need authentication, but the targeted user must already be authenticated and interact with the crafted link.
Are specific endpoints known to be vulnerable?
Yes. The identified GET endpoints are /account/protected/delAll, /account/protected/sub/delSub, and /message/updateAction.