Unrestricted File Upload Vulnerability in ZeroWdd Student Manager Software
CVE-2024-13134

5.3MEDIUM

Key Information:

Vendor
Zerowdd
Status
Studentmanager
Vendor
CVE Published:
5 January 2025

Badges

👾 Exploit Exists

Summary

A significant vulnerability exists in the ZeroWdd Student Manager software, specifically within the addTeacher/editTeacher functions of the TeacherController.java file. This flaw allows for unrestricted file uploads due to improper handling of input arguments. As a result, attackers can exploit this vulnerability remotely, posing severe security risks to the affected systems. The exploit has already been made public, heightening the urgency for users to mitigate potential threats by applying necessary security patches and updates.

Affected Version(s)

studentmanager 1.0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • 🟡

    Public PoC available

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

LVZC (VulDB User)
.