A vulnerability was detected in xiweicheng TMS up to 2.28.0. Affected by this issue is the function Upload of the file src/main/java/com/lhjz/portal/controller/FileController.java. The manipulation of the argument filename results in unrestricted upload. The attack may be performed from remote. The exploit is now public and may be used.
References
Configurations
No configuration.
History
17 Jan 2026, 19:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-01-17 19:15
Updated : 2026-01-26 15:05
NVD link : CVE-2026-1061
Mitre link : CVE-2026-1061
CVE.ORG link : CVE-2026-1061
JSON object : View
Products Affected
No product.
