CVE-2026-6487 | Qihui jtbc5 CMS 5.0.3.6 Code Endpoint manage.php path path traversal
A vulnerability was found in Qihui jtbc5 CMS 5.0.3.6. It has been classified as problematic. Affected is an unknown function of the file /dev/code/common/diplomat/manage.php of the component Code Endpoint. This manipulation of the argument path causes path traversal.
This vulnerability is tracked as CVE-2026-6487. The attack is possible to be carried out remotely. Moreover, an exploit is present.
The vendor was contacted early about this disclosure but did not respond in any way.