← Back to CVE search

CVE-2026-75339

cjbi admin3

Description

The storage endpoint /storage/upload of cjbi admin3 v3.0.0 are missing permission checks. /Any logged-in user can upload arbitrary files, and any anonymous attacker can download them.

EPSS 0.149%Risk 0
View source
Published
2026-08-28 00:18:12
Affected versions
==3.0.0
Type
Web application
Last modified
2026-08-28 00:18:12
Vector
Pending