CVE 5.3 MEDIUM

xiweicheng TMS HtmlUtil.java summary server-side request forgery_CVE-2026-1062

5.3 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P

Description

A flaw has been found in xiweicheng TMS up to 2.28.0. This affects the function Summary of the file src/main/java/com/lhjz/portal/util/HtmlUtil.java. This manipulation of the argument url causes server-side request forgery. It is possible to initiate the attack remotely. The exploit has been published and may be used.

Basic Information

ID CVE-2026-1062
Source VulDB
Published Jan 17, 2026 at 19:32

Affected Product

Vendor xiweicheng
Product TMS
Version 2.0
Affected Versions xiweicheng TMS 2.0
xiweicheng TMS 2.1
xiweicheng TMS 2.2
xiweicheng TMS 2.3
xiweicheng TMS 2.4
xiweicheng TMS 2.5
xiweicheng TMS 2.6
xiweicheng TMS 2.7
xiweicheng TMS 2.8
xiweicheng TMS 2.9
xiweicheng TMS 2.10
xiweicheng TMS 2.11
xiweicheng TMS 2.12
xiweicheng TMS 2.13
xiweicheng TMS 2.14
xiweicheng TMS 2.15
xiweicheng TMS 2.16
xiweicheng TMS 2.17
xiweicheng TMS 2.18
xiweicheng TMS 2.19
xiweicheng TMS 2.20
xiweicheng TMS 2.21
xiweicheng TMS 2.22
xiweicheng TMS 2.23
xiweicheng TMS 2.24
xiweicheng TMS 2.25
xiweicheng TMS 2.26
xiweicheng TMS 2.27
xiweicheng TMS 2.28.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.