PT-2025-2049 · Unknown · Zerowdd Myblog

Lvzc1

+1

·

Published

2025-01-08

·

Updated

2025-01-09

·

CVE-2024-13191

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ZeroWdd myblog version 1.0
Description A critical issue has been found in the upload function of the file src/main/java/com/wdd/myblog/controller/admin/uploadController.java. The manipulation of the file argument leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Recommendations For ZeroWdd myblog version 1.0, as a temporary workaround, consider disabling the upload function in the uploadController.java file until a patch is available. Restrict access to the src/main/java/com/wdd/myblog/controller/admin/uploadController.java file to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Access Control

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2024-13191

Affected Products

Zerowdd Myblog