PT-2026-22535 · Thinkgem · Jeesite
Saul1213
+1
·
Publicado
2026-03-02
·
Atualizado
2026-03-09
·
CVE-2026-3404
CVSS v3.1
8.1
Alta
| Vetor | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
thinkgem JeeSite versions up to 5.15.1
Description
A flaw exists in thinkgem JeeSite, potentially allowing for xml external entity reference. This issue is related to a function within the file
/com/jeesite/common/shiro/cas/CasOutHandler.java of the Endpoint component. The attack can be performed remotely and is considered highly complex, with difficult exploitability. The exploit has been published. The vendor was contacted but did not respond.Recommendations
Versions prior to 5.15.1 should be updated.
Exploit
Correção
XXE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Jeesite