CVE-2026-1062 | xiweicheng TMS up to 2.28.0 HtmlUtil.java summary url server-side request forgery (EUVD-2026-3131)
A vulnerability, which was classified as critical, has been found in xiweicheng TMS up to 2.28.0. This affects the function Summary of the file src/main/java/com/lhjz/portal/util/HtmlUtil.java. This manipulation of the argument url causes server-side request forgery.
The identification of this vulnerability is CVE-2026-1062. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.