Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
2.3

thinkgem JeeSite CAS Handler XML Injection

CVE-2026-3404
Summary

A security flaw in thinkgem JeeSite's CAS handler can be exploited by a remote attacker to inject malicious XML code, potentially leading to unauthorized access or other security breaches. This issue affects thinkgem JeeSite versions up to 5.15.1. The vendor has not acknowledged or addressed this issue.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versionsFix available
jeesite jeesite <= 5.15.1 –
Original title
A flaw has been found in thinkgem JeeSite up to 5.15.1. Impacted is an unknown function of the file /com/jeesite/common/shiro/cas/CasOutHandler.java of the component Endpoint. Executing a manipulat...
Original description
A flaw has been found in thinkgem JeeSite up to 5.15.1. Impacted is an unknown function of the file /com/jeesite/common/shiro/cas/CasOutHandler.java of the component Endpoint. Executing a manipulation can lead to xml external entity reference. The attack may be performed from remote. Attacks of this nature are highly complex. The exploitability is considered difficult. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
nvd CVSS2.0 4.6
nvd CVSS3.1 5.0
nvd CVSS4.0 2.3
Vulnerability type
CWE-610
CWE-611 XML External Entity (XXE)
Published: 2 Mar 2026 · Updated: 13 Mar 2026 · First seen: 6 Mar 2026