Information Disclosure Vulnerability in Tsinghua Unigroup Electronic Archives Management System
CVE-2024-13042

5.3MEDIUM

Key Information:

Vendor
CVE Published:
30 December 2024

What is CVE-2024-13042?

A vulnerability exists in Tsinghua Unigroup's Electronic Archives Management System that compromises the download functionality of the SubjectController.class.php file. This flaw allows attackers to manipulate the path argument, which can lead to unauthorized information disclosure. The nature of this vulnerability permits remote exploitation, thus making it critical for users to take precautionary measures. With the exploit details publicly disclosed, systems running version 3.2.210802(62532) are particularly at risk. Immediate attention to mitigating this vulnerability is essential to safeguard sensitive information from potential exposure.

Affected Version(s)

Electronic Archives Management System 3.2.210802(62532)

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

.