PT-2026-21452 · Dromara · Dromara Ujcms

Saul1213

·

Published

2026-02-22

·

Updated

2026-02-23

·

CVE-2026-2953

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dromara UJCMS version 101.2
Description A path traversal issue exists in Dromara UJCMS version 101.2. This is due to manipulation of the deleteDirectory function within the WebFileTemplateController.delete file of the Template Handler component. The attack can be performed remotely. The exploit has been publicly disclosed.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2026-2953

Affected Products

Dromara Ujcms