Unrestricted File Upload Vulnerability in My-Blog by ZHENFENG13
CVE-2024-13144

5.3MEDIUM

Key Information:

Vendor
Zhenfeng13
Status
My-blog
Vendor
CVE Published:
6 January 2025

Summary

A vulnerability exists in the My-Blog product by ZHENFENG13, specifically in the uploadFileByEditomd function within the BlogController.java file. This flaw enables attackers to perform unrestricted file uploads through manipulation of the editormd-image-file argument. As a result, this opens the door for potential remote exploitation, exposing systems to significant risk. The details of this vulnerability have been made publicly available, heightening concerns for users of My-Blog 1.0. Immediate action should be taken to mitigate this risk.

Affected Version(s)

My-Blog 1.0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

Credit

LVZC1 (VulDB User)
.