PT-2026-21557 · Jeewms+1 · Jeewms+1

Din4

·

Published

2026-02-23

·

Updated

2026-02-28

·

CVE-2026-3026

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions erzhongxmu JEEWMS version 3.7
Description A server-side request forgery issue exists due to the manipulation of the upfile argument in the /plug-in/ueditor/jsp/getRemoteImage.jsp file. This can be exploited remotely. The exploit has been publicly disclosed. The vendor was contacted but did not respond.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SSRF

Weakness Enumeration

Related Identifiers

CVE-2026-3026

Affected Products

Jeewms
Ueditor