Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-50895 | A vulnerability classified as problematic has been found in Dromara UJCMS up to 9.6.3. This affects an unknown part of the file /users/id of the component User ID Handler. The manipulation leads to authorization bypass. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 13 Dec 2024 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ujcms
Ujcms ujcms |
|
| CPEs | cpe:2.3:a:ujcms:ujcms:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Ujcms
Ujcms ujcms |
Wed, 11 Dec 2024 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 11 Dec 2024 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability classified as problematic has been found in Dromara UJCMS up to 9.6.3. This affects an unknown part of the file /users/id of the component User ID Handler. The manipulation leads to authorization bypass. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. | |
| Title | Dromara UJCMS User ID id authorization | |
| Weaknesses | CWE-285 CWE-639 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2024-12-11T21:27:41.611Z
Reserved: 2024-12-11T12:37:38.381Z
Link: CVE-2024-12483
Updated: 2024-12-11T21:27:38.166Z
Status : Analyzed
Published: 2024-12-12T01:40:29.600
Modified: 2024-12-13T17:12:32.377
Link: CVE-2024-12483
No data.
OpenCVE Enrichment
No data.
EUVD