Information Disclosure Vulnerability in Tsinghua Unigroup Electronic Archives Management System
CVE-2024-13042
5.3MEDIUM
What is CVE-2024-13042?
A vulnerability exists in Tsinghua Unigroup's Electronic Archives Management System that compromises the download functionality of the SubjectController.class.php file. This flaw allows attackers to manipulate the path argument, which can lead to unauthorized information disclosure. The nature of this vulnerability permits remote exploitation, thus making it critical for users to take precautionary measures. With the exploit details publicly disclosed, systems running version 3.2.210802(62532) are particularly at risk. Immediate attention to mitigating this vulnerability is essential to safeguard sensitive information from potential exposure.
Affected Version(s)
Electronic Archives Management System 3.2.210802(62532)