← Retour à la recherche de CVE

CVE-2026-75339

cjbi admin3

Description

The storage endpoint /storage/upload of cjbi admin3 v3.0.0 are missing permission checks. /Any logged-in user can upload arbitrary files, and any anonymous attacker can download them.

EPSS 0.149%Risque 0
Voir la source
Publication
2026-08-28 00:18:12
Versions concernées
==3.0.0
Type
Application web
Dernière modification
2026-08-28 00:18:12
Vecteur
Pending