PT-2024-17616 · Dromara · Dromara Ujcms
Vastzero
·
Published
2024-12-11
·
Updated
2024-12-13
·
CVE-2024-12483
CVSS v3.1
5.9
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Dromara UJCMS versions up to 9.6.3
Description
A problematic vulnerability has been found in Dromara UJCMS, affecting an unknown part of the file
/users/id of the component User ID Handler. The manipulation leads to authorization bypass. It is possible to initiate the attack remotely. The complexity of an attack is rather high, and the exploitability is told to be difficult.Recommendations
For versions up to 9.6.3, as a temporary workaround, consider restricting access to the
/users/id endpoint until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Improper Authorization
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Dromara Ujcms