A vulnerability was found in Jinan Chicheng Company JFlow 2.0.0. It has been rated as problematic. This issue affects the function AttachmentUploadController of the file /WF/Ath/EntityMutliFile_Load.do of the component Attachment Handler. The manipulation of the argument oid leads to improper access controls. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
References
Link | Resource |
---|---|
https://github.com/sweatxi/BugHub/blob/main/Jinan%20Gallop%20JFlow%20CMS%20port%20is%20not%20authorized%20to%20cause%20the%20leakage%20of%20database%20attachment%20information.pdf | Broken Link |
https://vuldb.com/?ctiid.278153 | Permissions Required |
https://vuldb.com/?id.278153 | Permissions Required |
https://vuldb.com/?submit.406225 | Third Party Advisory |
Configurations
History
25 Sep 2024, 17:18
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:jflow_project:jflow:2.0.0:*:*:*:*:*:*:* | |
CWE | NVD-CWE-Other | |
References | () https://github.com/sweatxi/BugHub/blob/main/Jinan%20Gallop%20JFlow%20CMS%20port%20is%20not%20authorized%20to%20cause%20the%20leakage%20of%20database%20attachment%20information.pdf - Broken Link | |
References | () https://vuldb.com/?ctiid.278153 - Permissions Required | |
References | () https://vuldb.com/?id.278153 - Permissions Required | |
References | () https://vuldb.com/?submit.406225 - Third Party Advisory | |
CVSS |
v2 : v3 : |
v2 : 4.0
v3 : 5.3 |
First Time |
Jflow Project
Jflow Project jflow |
20 Sep 2024, 12:30
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
19 Sep 2024, 21:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-09-19 21:15
Updated : 2024-09-25 17:18
NVD link : CVE-2024-9003
Mitre link : CVE-2024-9003
CVE.ORG link : CVE-2024-9003
JSON object : View
Products Affected
jflow_project
- jflow
CWE