CVE-2026-107828 PUBLISHED

Jivejdon through 5.0 Predictable Passwords via Sina Weibo OAuth Login

Assigner: VulnCheck
Reserved: 08.10.2026 Published: 08.10.2026 Updated: 09.10.2026

Jivejdon through 5.0 contains an authentication bypass vulnerability that allows unauthenticated attackers to access Weibo-created accounts by deriving predictable credentials from public Weibo user IDs. OAuthAccountServiceImp.transferSina() sets the password to the first four digits of the Weibo ID, letting attackers log in through normal form login to read or post as victims.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
CVSS Score: 6.9

Product Status

Vendor banq
Product jivejdon
Versions Default: unaffected
  • affected from 0 to 5.0 (incl.)

Credits

  • Ikram-4 finder

References

Problem Types

  • Use of Weak Credentials CWE