5.3
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Description
A vulnerability was detected in xiweicheng TMS up to 2.28.0. Affected by this issue is the function Upload of the file src/main/java/com/lhjz/portal/controller/FileController.java. The manipulation of the argument filename results in unrestricted upload. The attack may be performed from remote. The exploit is now public and may be used.
Basic Information
ID
CVE-2026-1061
Source
VulDB
Published
Jan 17, 2026 at 19:02
Affected Product
Vendor
xiweicheng
Product
TMS
Version
2.0
Affected Versions
xiweicheng TMS 2.0
xiweicheng TMS 2.1
xiweicheng TMS 2.2
xiweicheng TMS 2.3
xiweicheng TMS 2.4
xiweicheng TMS 2.5
xiweicheng TMS 2.6
xiweicheng TMS 2.7
xiweicheng TMS 2.8
xiweicheng TMS 2.9
xiweicheng TMS 2.10
xiweicheng TMS 2.11
xiweicheng TMS 2.12
xiweicheng TMS 2.13
xiweicheng TMS 2.14
xiweicheng TMS 2.15
xiweicheng TMS 2.16
xiweicheng TMS 2.17
xiweicheng TMS 2.18
xiweicheng TMS 2.19
xiweicheng TMS 2.20
xiweicheng TMS 2.21
xiweicheng TMS 2.22
xiweicheng TMS 2.23
xiweicheng TMS 2.24
xiweicheng TMS 2.25
xiweicheng TMS 2.26
xiweicheng TMS 2.27
xiweicheng TMS 2.28.0
xiweicheng TMS 2.1
xiweicheng TMS 2.2
xiweicheng TMS 2.3
xiweicheng TMS 2.4
xiweicheng TMS 2.5
xiweicheng TMS 2.6
xiweicheng TMS 2.7
xiweicheng TMS 2.8
xiweicheng TMS 2.9
xiweicheng TMS 2.10
xiweicheng TMS 2.11
xiweicheng TMS 2.12
xiweicheng TMS 2.13
xiweicheng TMS 2.14
xiweicheng TMS 2.15
xiweicheng TMS 2.16
xiweicheng TMS 2.17
xiweicheng TMS 2.18
xiweicheng TMS 2.19
xiweicheng TMS 2.20
xiweicheng TMS 2.21
xiweicheng TMS 2.22
xiweicheng TMS 2.23
xiweicheng TMS 2.24
xiweicheng TMS 2.25
xiweicheng TMS 2.26
xiweicheng TMS 2.27
xiweicheng TMS 2.28.0