PT-2026-22535 · Thinkgem · Jeesite
Saul1213
+1
·
Published
2026-03-02
·
Updated
2026-03-09
·
CVE-2026-3404
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
thinkgem JeeSite versions up to 5.15.1
Description
A flaw exists in thinkgem JeeSite, potentially allowing for xml external entity reference. This issue is related to a function within the file
/com/jeesite/common/shiro/cas/CasOutHandler.java of the Endpoint component. The attack can be performed remotely and is considered highly complex, with difficult exploitability. The exploit has been published. The vendor was contacted but did not respond.Recommendations
Versions prior to 5.15.1 should be updated.
Exploit
Fix
XXE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Jeesite