The tumbnail API of Tronclass from WisdomGarden lacks proper access control, allowing unauthenticated remote attackers to obtain certain specific files by modifying the URL.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published: 2024-07-15T02:50:39.639Z

Updated: 2024-08-01T21:41:04.604Z

Reserved: 2024-07-15T02:29:39.882Z

Link: CVE-2024-6738

cve-icon Vulnrichment

Updated: 2024-08-01T21:41:04.604Z

cve-icon NVD

Status : Analyzed

Published: 2024-07-15T03:15:03.293

Modified: 2024-07-16T14:06:27.810

Link: CVE-2024-6738

cve-icon Redhat

No data.