Description


Jivejdon through 5.0 contains an authentication bypass vulnerability that allows unauthenticated attackers to access Weibo-created accounts by deriving predictable credentials from public Weibo user IDs. OAuthAccountServiceImp.transferSina() sets the password to the first four digits of the Weibo ID, letting attackers log in through normal form login to read or post as victims.

Related CPE's


Could not find any relations

Weaknesses



CWE-1391

CVSS impact metrics


CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

6.5 · Medium

Information


Source identifier

[email protected]

Vulnerability status

Deferred

Published

2026-10-08T22:17:30.480Z

20 hours ago

Last modified

2026-10-09T16:45:01.980Z

1 hour ago