Metrics
Affected Vendors & Products
Thu, 09 Jan 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 09 Jan 2025 03:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability was found in donglight bookstore电商书城系统说明 1.0. It has been declared as critical. Affected by this vulnerability is the function uploadPicture of the file src/main/java/org/zdd/bookstore/web/controller/admin/AdminBookController. java. The manipulation of the argument pictureFile leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. | |
Title | donglight bookstore电商书城系统说明 AdminBookController. java uploadPicture unrestricted upload | |
Weaknesses | CWE-284 CWE-434 |
|
References |
| |
Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2025-01-09T03:31:04.605Z
Updated: 2025-01-09T15:47:47.154Z
Reserved: 2025-01-08T16:49:04.907Z
Link: CVE-2024-13210
Updated: 2025-01-09T15:47:26.272Z
Status : Received
Published: 2025-01-09T04:15:11.890
Modified: 2025-01-09T04:15:11.890
Link: CVE-2024-13210
No data.