WisdomGarden Tronclass has improper access control when uploading file. An authenticated remote attacker with general user privilege can exploit this vulnerability to access files belonging to other users by modifying the file ID within URL.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published: 2023-03-27T00:00:00

Updated: 2024-08-02T11:03:19.255Z

Reserved: 2023-01-31T00:00:00

Link: CVE-2023-24834

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2023-03-27T04:15:09.660

Modified: 2023-04-18T13:32:37.937

Link: CVE-2023-24834

cve-icon Redhat

No data.