Missing Authorization in Jivejdon Allows Thread Manipulation by Authenticated Users
CVE-2026-107792
5.3MEDIUM
What is CVE-2026-107792?
Jivejdon contains a vulnerability in the UpdateThreadToForumAction process that permits authenticated users to exploit missing authorization. This vulnerability allows attackers to manipulate forum threads by relocating reply-less threads to arbitrary forums through specially crafted parameters in API calls. The affected component can be exploited by sending manipulated threadId and forumId values to the endpoint /message/threadToForum/save, enabling unauthorized movement of thread content. This security oversight emphasizes the importance of implementing stringent authorization checks to prevent misuse.
Affected Version(s)
jivejdon d58a36b03676e70044b8fab5cb66d21eb83a023d
