Description
An arbitrary File download vulnerability exists in Novel-Plus v4.3.0-RC1 and prior at com.java2nb.common.controller.FileController: fileDownload(). An attacker can pass in specially crafted filePath and fieName parameters to perform arbitrary File download.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-19T20:06:10.285Z
Reserved: 2024-01-25T00:00:00.000Z
Link: CVE-2024-24024
Updated: 2024-08-01T23:19:51.258Z
Status : Modified
Published: 2024-02-08T01:15:27.113
Modified: 2024-11-21T08:58:50.610
Link: CVE-2024-24024
No data.
OpenCVE Enrichment
No data.
Weaknesses