Cross-Site Request Forgery Vulnerability in Jivejdon by Banq
CVE-2026-107831
5.3MEDIUM
What is CVE-2026-107831?
Jivejdon versions up to 5.0 are susceptible to cross-site request forgery, enabling remote attackers to exploit GET endpoints without anti-CSRF tokens. By enticing authenticated users to click on malicious links directed at specific endpoints such as /account/protected/delAll or /message/updateAction, attackers can execute unauthorized actions like deleting private messages or altering thread names. This vulnerability poses a significant risk as it can lead to unintended state changes in user accounts.
Affected Version(s)
jivejdon 0 <= 5.0
