CVE-2026-3027

A vulnerability was found in erzhongxmu JEEWMS up to 3.7. This affects an unknown part of the file src/main/webapp/plug-in/ueditor/jsp/getContent.jsp of the component UEditor. The manipulation of the argument myEditor results in cross site scripting. The attack can be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Configurations

Configuration 1 (hide)

cpe:2.3:a:jeewms:jeewms:*:*:*:*:*:*:*:*

History

24 Feb 2026, 20:03

Type Values Removed Values Added
References () https://vuldb.com/?ctiid.347383 - () https://vuldb.com/?ctiid.347383 - Permissions Required
References () https://vuldb.com/?id.347383 - () https://vuldb.com/?id.347383 - Third Party Advisory
References () https://vuldb.com/?submit.756523 - () https://vuldb.com/?submit.756523 - Third Party Advisory
References () https://www.notion.so/JEEWMS-Reflected-XSS-Vulnerability-in-UEditor-Module-304ea92a3c41806a97ffc9b707f2fbf0 - () https://www.notion.so/JEEWMS-Reflected-XSS-Vulnerability-in-UEditor-Module-304ea92a3c41806a97ffc9b707f2fbf0 - Exploit, Third Party Advisory
Summary
  • (es) Se encontró una vulnerabilidad en erzhongxmu JEEWMS hasta la versión 3.7. Esto afecta una parte desconocida del archivo src/main/webapp/plug-in/ueditor/jsp/getContent.jsp del componente UEditor. Manipular el argumento myEditor provoca un cross-site scripting. El ataque puede lanzarse en remoto. El exploit se ha hecho público y podría utilizarse. Se contactó con el proveedor con anterioridad a la divulgación, pero no respondió de ninguna manera.
First Time Jeewms
Jeewms jeewms
CPE cpe:2.3:a:jeewms:jeewms:*:*:*:*:*:*:*:*

23 Feb 2026, 21:19

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-23 21:19

Updated : 2026-02-24 20:03


NVD link : CVE-2026-3027

Mitre link : CVE-2026-3027

CVE.ORG link : CVE-2026-3027


JSON object : View

Products Affected

jeewms

  • jeewms
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CWE-94

Improper Control of Generation of Code ('Code Injection')