CVE 5.3 MEDIUM

xiweicheng TMS FileController.java upload unrestricted upload_CVE-2026-1061

5.3 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P

Description

A vulnerability was detected in xiweicheng TMS up to 2.28.0. Affected by this issue is the function Upload of the file src/main/java/com/lhjz/portal/controller/FileController.java. The manipulation of the argument filename results in unrestricted upload. The attack may be performed from remote. The exploit is now public and may be used.

Basic Information

ID CVE-2026-1061
Source VulDB
Published Jan 17, 2026 at 19:02

Affected Product

Vendor xiweicheng
Product TMS
Version 2.0
Affected Versions xiweicheng TMS 2.0
xiweicheng TMS 2.1
xiweicheng TMS 2.2
xiweicheng TMS 2.3
xiweicheng TMS 2.4
xiweicheng TMS 2.5
xiweicheng TMS 2.6
xiweicheng TMS 2.7
xiweicheng TMS 2.8
xiweicheng TMS 2.9
xiweicheng TMS 2.10
xiweicheng TMS 2.11
xiweicheng TMS 2.12
xiweicheng TMS 2.13
xiweicheng TMS 2.14
xiweicheng TMS 2.15
xiweicheng TMS 2.16
xiweicheng TMS 2.17
xiweicheng TMS 2.18
xiweicheng TMS 2.19
xiweicheng TMS 2.20
xiweicheng TMS 2.21
xiweicheng TMS 2.22
xiweicheng TMS 2.23
xiweicheng TMS 2.24
xiweicheng TMS 2.25
xiweicheng TMS 2.26
xiweicheng TMS 2.27
xiweicheng TMS 2.28.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.