Unrestricted File Upload Vulnerability in ZeroWdd Student Manager Software
CVE-2024-13134
5.3MEDIUM
Key Information:
- Vendor
- Zerowdd
- Status
- Studentmanager
- Vendor
- CVE Published:
- 5 January 2025
Badges
👾 Exploit Exists
Summary
A significant vulnerability exists in the ZeroWdd Student Manager software, specifically within the addTeacher/editTeacher functions of the TeacherController.java file. This flaw allows for unrestricted file uploads due to improper handling of input arguments. As a result, attackers can exploit this vulnerability remotely, posing severe security risks to the affected systems. The exploit has already been made public, heightening the urgency for users to mitigate potential threats by applying necessary security patches and updates.
Affected Version(s)
studentmanager 1.0
References
CVSS V4
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved
Credit
LVZC (VulDB User)