Jtbc develops a narrowly scoped PHP-based web application and related components that present a modest but concentrated vulnerability footprint centered on application-layer input handling and request validation. The recurring weakness classes—cross-site scripting, cross-site request forgery, path traversal, and unrestricted file upload—reflect typical exposure points in web applications lacking robust input filtering and access controls. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Jtbc over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-17429HIGH /console/account/manage.php?type=action&action=add in JTBC v3.0(C) has CSRF for adding an administrator account. | Mar 7, 2019 | 8.8 | 28 | NO | NO |
CVE-2018-19546HIGH JTBC(PHP) 3.0.1.7 has CSRF via the console/xml/manage.php?type=action&action=edit URI, as demonstrated by an XSS payload in the content parameter. | Nov 26, 2018 | 8.8 | 27 | NO | NO |
CVE-2018-18436HIGH JTBC(PHP) 3.0 allows CSRF for creating an account via the console/account/manage.php?type=action&action=add URI. | Oct 17, 2018 | 8.8 | 27 | NO | NO |
CVE-2018-17836HIGH An issue was discovered in JTBC(PHP) 3.0.1.6. It allows remote attackers to execute arbitrary PHP code by using a /console/file/manage.php?type=action&action=addfile&path=..%2F sub | Oct 1, 2018 | 8.8 | 27 | NO | NO |
CVE-2018-19327HIGH An issue was discovered in JTBC(PHP) 3.0.1.7. aboutus/manage.php?type=action&action=add allows CSRF. | Nov 17, 2018 | 8.8 | 26 | NO | NO |
CVE-2018-17838HIGH An issue was discovered in JTBC(PHP) 3.0.1.6. Arbitrary file read operations are possible via a /console/#/console/file/manage.php?type=list&path=c:/ substring. | Oct 1, 2018 | 7.5 | 24 | NO | NO |
CVE-2018-17837HIGH An issue was discovered in JTBC(PHP) 3.0.1.6. Arbitrary file deletion is possible via a /console/file/manage.php?type=action&action=delete&path=c%3A%2F substring. | Oct 1, 2018 | 7.5 | 24 | NO | NO |
CVE-2018-19547MEDIUM JTBC(PHP) 3.0.1.7 has XSS via the console/xml/manage.php?type=action&action=edit content parameter. | Nov 26, 2018 | 6.1 | 21 | NO | NO |
CVE-2019-9662HIGH An issue was discovered in JTBC(PHP) 3.0.1.8. Its cache management module is flawed. An arbitrary file ending in "inc.php" can be deleted via a console/cache/manage.php?type=action | Mar 11, 2019 | 7.5 | 19 | NO | NO |
CVE-2019-8433HIGH JTBC(PHP) 3.0.1.8 allows Arbitrary File Upload via the console/#/console/file/manage.php?type=list URI, as demonstrated by a .php file. | Feb 18, 2019 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Jtbc.
Media articles that mention a CVE ID that affects a product developed by Jtbc — matched by CVE ID, not by vendor name.