PT-2026-22535 · Thinkgem · Jeesite

Saul1213

+1

·

Publicado

2026-03-02

·

Atualizado

2026-03-09

·

CVE-2026-3404

CVSS v3.1

8.1

Alta

VetorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions thinkgem JeeSite versions up to 5.15.1
Description A flaw exists in thinkgem JeeSite, potentially allowing for xml external entity reference. This issue is related to a function within the file /com/jeesite/common/shiro/cas/CasOutHandler.java of the Endpoint component. The attack can be performed remotely and is considered highly complex, with difficult exploitability. The exploit has been published. The vendor was contacted but did not respond.
Recommendations Versions prior to 5.15.1 should be updated.

Exploit

Correção

XXE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-3404

Produtos afetados

Jeesite