PT-2024-39187 · Unknown · Yunke Online School System
Jackieya
+1
·
Published
2024-09-11
·
Updated
2024-09-12
·
CVE-2024-8707
CVSS v2.0
4.0
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Yunke Online School System versions up to 3.0.6
Description:
A vulnerability was found in the Yunke Online School System, affecting the
downfile function of the file application/admin/controller/Appadmin.php. The manipulation of the url argument leads to path traversal. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.Recommendations:
For versions up to 3.0.6, as a temporary workaround, consider disabling the
downfile function until a patch is available. Restrict access to the application/admin/controller/Appadmin.php file to minimize the risk of exploitation. Avoid using the url argument in the affected function until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Yunke Online School System