Description
A flaw has been found in xiweicheng TMS up to 2.28.0. This affects the function Summary of the file src/main/java/com/lhjz/portal/util/HtmlUtil.java. This manipulation of the argument url causes server-side request forgery. It is possible to initiate the attack remotely. The exploit has been published and may be used.
Problem types
Product status
2.1
2.2
2.3
2.4
2.5
2.6
2.7
2.8
2.9
2.10
2.11
2.12
2.13
2.14
2.15
2.16
2.17
2.18
2.19
2.20
2.21
2.22
2.23
2.24
2.25
2.26
2.27
2.28.0
Timeline
| 2026-01-16: | Advisory disclosed |
| 2026-01-16: | VulDB entry created |
| 2026-01-18: | VulDB entry last update |
Credits
youran (VulDB User)
References
vuldb.com/?id.341630 (VDB-341630 | xiweicheng TMS HtmlUtil.java summary server-side request forgery)
vuldb.com/?ctiid.341630 (VDB-341630 | CTI Indicators (IOB, IOC, IOA))
vuldb.com/?submit.731241 (Submit #731241 | https://gitee.com/xiweicheng/tms/ Merchant Mall - Mall Development/TMS 1.0 Server-Side Request Forgery)
vuldb.com/?submit.731242 (Submit #731242 | https://gitee.com/xiweicheng/tms/ Merchant Mall - Mall Development/TMS 1.0 Server-Side Request Forgery (Duplicate))
github.com/.../商户商城—商城开发tms/SSRF(1).md
github.com/.../商户商城—商城开发tms/SSRF(2).md