A vulnerability was found in Dromara UJCMS 10.0.2. Impacted is the function importChanel of the file /api/backend/ext/import-data/import-channel of the component ImportDataController. Performing a manipulation of the argument driverClassName/url results in injection. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Metrics
Affected Vendors & Products
References
History
Sun, 22 Feb 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was found in Dromara UJCMS 10.0.2. Impacted is the function importChanel of the file /api/backend/ext/import-data/import-channel of the component ImportDataController. Performing a manipulation of the argument driverClassName/url results in injection. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | Dromara UJCMS ImportDataController import-channel importChanel injection | |
| First Time appeared |
Ujcms
Ujcms ujcms |
|
| Weaknesses | CWE-707 CWE-74 |
|
| CPEs | cpe:2.3:a:ujcms:ujcms:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Ujcms
Ujcms ujcms |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-02-22T15:02:17.390Z
Reserved: 2026-02-21T21:11:15.185Z
Link: CVE-2026-2954
No data.
Status : Received
Published: 2026-02-22T15:16:16.610
Modified: 2026-02-22T15:16:16.610
Link: CVE-2026-2954
No data.
OpenCVE Enrichment
No data.