Metrics
Affected Vendors & Products
Mon, 06 Jan 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 06 Jan 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Title | zhenfeng13 My-Blog BlogController.java uploadFileByEditomd unrestricted upload | |
Metrics |
cvssV4_0
|
cvssV3_0
|
Mon, 06 Jan 2025 00:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability classified as critical has been found in zhenfeng13 My-Blog 1.0. Affected is the function uploadFileByEditomd of the file src/main/java/com/site/blog/my/core/controller/admin/BlogController.java. The manipulation of the argument editormd-image-file leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. | |
Weaknesses | CWE-284 CWE-434 |
|
References |
| |
Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2025-01-06T00:00:13.019Z
Updated: 2025-01-06T13:40:54.938Z
Reserved: 2025-01-05T09:14:01.391Z
Link: CVE-2024-13144
Updated: 2025-01-06T13:40:50.402Z
Status : Received
Published: 2025-01-06T00:15:05.633
Modified: 2025-01-06T00:15:05.633
Link: CVE-2024-13144
No data.