PT-2026-22535 · Thinkgem · Jeesite

Saul1213

+1

·

Published

2026-03-02

·

Updated

2026-03-09

·

CVE-2026-3404

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions thinkgem JeeSite versions up to 5.15.1
Description A flaw exists in thinkgem JeeSite, potentially allowing for xml external entity reference. This issue is related to a function within the file /com/jeesite/common/shiro/cas/CasOutHandler.java of the Endpoint component. The attack can be performed remotely and is considered highly complex, with difficult exploitability. The exploit has been published. The vendor was contacted but did not respond.
Recommendations Versions prior to 5.15.1 should be updated.

Exploit

Fix

XXE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-3404

Affected Products

Jeesite