Executive brief
CodeLibs Fess, an enterprise search server, contains a security vulnerability in its administrative design interface. An attacker with administrative privileges can inject malicious code into the system by manipulating file content through the JSP File Handler. This could allow an attacker to compromise the server's integrity or gain unauthorized access to data, though it requires high-level access to perform.
Technical details
A code injection vulnerability exists in CodeLibs Fess versions up to 15.5.1 within the JSP File Handler component. The flaw is located in the 'update' function of 'AdminDesignAction.java'. By manipulating the 'content' argument, a remote attacker with high privileges (PR:H) can inject and execute arbitrary code. The vulnerability is classified under CWE-94 (Improper Control of Generation of Code) and CWE-74 (Injection). A public exploit (PoC) is available, and the vendor has reportedly not responded to disclosure attempts.
Affected products
- CodeLibs Fess up to 15.5.1
Timeline
- 2026-05-09: disclosed: Initial disclosure date
- 2026-05-09: advisory: NVD publication date