PT-2025-2055 · Unknown · Donglight Bookstore电商书城系统说明

Lvzc2

·

Published

2025-01-09

·

Updated

2025-01-09

·

CVE-2024-13197

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions donglight bookstore电商书城系统说明 version 1.0.0
Description A vulnerability was found in the updateUser function of the file src/main/Java/org/zdd/bookstore/web/controller/admin/AdminUserControlle.java. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Recommendations For version 1.0.0, as a temporary workaround, consider disabling the updateUser function until a patch is available. Restrict access to the AdminUserControlle.java file to minimize the risk of exploitation. Avoid using the updateUser function in the affected file until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2024-13197

Affected Products

Donglight Bookstore电商书城系统说明