Stored Cross-Site Scripting Vulnerability in Jivejdon Application by Banq
CVE-2026-107801

5.1MEDIUM

Key Information:

Vendor

Banq

Status
Vendor
CVE Published:
8 October 2026

What is CVE-2026-107801?

Jivejdon, a popular application developed by Banq, has a vulnerability that allows authenticated users to perform stored cross-site scripting (XSS) attacks. This occurs when attackers exploit the file upload functionality by submitting files with a manipulated Content-Type, such as text/html. This enables the attacker to craft a malicious JavaScript that, when linked and accessed by other users, executes within the application context. Such vulnerabilities pose significant risks, potentially leading to data theft, session hijacking, and further exploitation of the web application.

Affected Version(s)

jivejdon 0 <= 5.0

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ikram-4
.