A vulnerability was found in wangl1989 mysiteforme 1.0. It has been declared as critical. This vulnerability affects the function upload of the file src/main/java/com/mysiteform/admin/service/ipl/LocalUploadServiceImpl. The manipulation of the argument test leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
History

Fri, 10 Jan 2025 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Wangl1989
Wangl1989 mysiteforme
CPEs cpe:2.3:a:wangl1989:mysiteforme:1.0:*:*:*:*:*:*:*
Vendors & Products Wangl1989
Wangl1989 mysiteforme

Mon, 06 Jan 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 05 Jan 2025 10:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in wangl1989 mysiteforme 1.0. It has been declared as critical. This vulnerability affects the function upload of the file src/main/java/com/mysiteform/admin/service/ipl/LocalUploadServiceImpl. The manipulation of the argument test leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Title wangl1989 mysiteforme LocalUploadServiceImpl upload unrestricted upload
Weaknesses CWE-284
CWE-434
References
Metrics cvssV2_0

{'score': 5.8, 'vector': 'AV:N/AC:L/Au:M/C:P/I:P/A:P'}

cvssV3_0

{'score': 4.7, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L'}

cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2025-01-06T15:54:18.624Z

Reserved: 2025-01-04T09:48:36.363Z

Link: CVE-2024-13138

cve-icon Vulnrichment

Updated: 2025-01-06T15:53:48.032Z

cve-icon NVD

Status : Analyzed

Published: 2025-01-05T11:15:05.747

Modified: 2025-01-10T21:01:57.583

Link: CVE-2024-13138

cve-icon Redhat

No data.