PT-2026-36131 · Jeesite · Jeesite

Arron-Bit

·

Published

2026-04-30

·

Updated

2026-05-12

·

CVE-2026-36760

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions JeeSite version 5.15.1
Description An issue in the '/a/file/upload' endpoint allows authenticated attackers with file upload permissions to perform path traversal and write arbitrary files with whitelisted suffixes to any location on the filesystem when chunked upload is enabled. This is possible via the fileMd5 parameter.
Recommendations As a temporary workaround, restrict access to the '/a/file/upload' endpoint or disable the chunked upload feature to prevent the use of the fileMd5 parameter for unauthorized file writes.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2026-36760

Affected Products

Jeesite