Jeesite 1.2.7 is affected by: XML External Entity (XXE). The impact is: sensitive information disclosure. The component is: convertToModel() function in src/main/java/com.thinkgem.jeesite/modules/act/service/ActProcessService.java. The attack vector is: network connectivity,authenticated,must upload a specially crafted xml file. The fixed version is: 4.0 and later.
Cite this page
CVE-2019-1010202. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2019-1010202
Use CWE-611, Jeesite vendor hub and Jeesite product page to widen CVE-2019-1010202 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2024-8112, CVE-2023-38991 and CVE-2025-5186 for nearby disclosures in the same product family.