CVE-2026-2953: Dromara UJCMS Template WebFileTemplateController.delete deleteDirectory path traversal
A vulnerability has been found in Dromara UJCMS 101.2. This issue affects the function deleteDirectory of the file WebFileTemplateController.delete of the component Template Handler. Such manipulation leads to path traversal. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2953?
CVE-2026-2953 is considered a high-severity vulnerability due to its potential for path traversal exploitation.
How do I fix CVE-2026-2953?
To fix CVE-2026-2953, update Dromara UJCMS to the latest version that addresses this path traversal vulnerability.
What components are affected by CVE-2026-2953?
CVE-2026-2953 affects the WebFileTemplateController.delete function in the Template Handler component of Dromara UJCMS.
What impact does CVE-2026-2953 have on my system?
CVE-2026-2953 can allow attackers to manipulate file paths, potentially leading to unauthorized access to sensitive files on the server.
Is there a workaround for CVE-2026-2953 if I cannot update?
While waiting for an update for CVE-2026-2953, implement access controls and validate user inputs to mitigate the risk of exploitation.