PT-2026-36151 · Jeesite · Jeesite

Arron-Bit

·

Published

2026-04-30

·

Updated

2026-04-30

·

CVE-2026-36762

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions JeeSite version 5.15.1
Description An issue in the '/a/file/upload' endpoint allows authenticated attackers with file upload permissions to perform path traversal. By manipulating the fileEntityId parameter, an attacker can write arbitrary files with whitelisted suffixes to arbitrary locations on the filesystem. Path traversal is a technique used to access files and directories that are stored outside the web root folder.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-36762

Affected Products

Jeesite