CVE-2026-107801
Received Received - Intake

Stored XSS in Jivejdon via Malicious File Upload

Vulnerability report for CVE-2026-107801, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: VulnCheck

Description

Jivejdon through 5.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to execute JavaScript by uploading attachments with an attacker-supplied Content-Type. Attackers can upload a file declared as text/html, which UploadShowAction serves inline, and share its link to run JavaScript on the application's origin for viewing users.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
banq jivejdon 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a stored cross-site scripting (XSS) flaw in Jivejdon version 5.0 or earlier. It allows authenticated attackers to inject malicious JavaScript by uploading files with a manipulated Content-Type header, such as declaring the file as text/html. When users view these attachments via UploadShowAction, the JavaScript executes in their browser within the application's domain.

Detection Guidance

To detect this vulnerability, inspect uploaded files for incorrect Content-Type headers. Check if files are served with text/html instead of their actual type. Review server logs for suspicious file uploads and verify if UploadShowAction serves files inline without proper validation.

Impact Analysis

If you are a user of a vulnerable Jivejdon instance, an attacker could trick you into clicking a link to a malicious file. This could lead to session hijacking, theft of sensitive data, or unauthorized actions performed on your behalf within the application. The impact depends on the permissions of the affected user.

Compliance Impact

This vulnerability could lead to unauthorized access to personal data, violating GDPR's data protection principles or HIPAA's safeguards for protected health information. Organizations using Jivejdon may face compliance violations, regulatory fines, or reputational damage if exploited.

Mitigation Strategies

Immediately update Jivejdon to the latest version. Implement strict file upload validation to reject files with text/html Content-Type. Configure servers to serve uploaded files with correct MIME types and disable inline execution of HTML content.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107801. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart