Unrestricted File Upload Vulnerability in My-Blog by ZHENFENG13
CVE-2024-13144
5.3MEDIUM
Key Information:
- Vendor
- Zhenfeng13
- Status
- My-blog
- Vendor
- CVE Published:
- 6 January 2025
Summary
A vulnerability exists in the My-Blog product by ZHENFENG13, specifically in the uploadFileByEditomd function within the BlogController.java file. This flaw enables attackers to perform unrestricted file uploads through manipulation of the editormd-image-file argument. As a result, this opens the door for potential remote exploitation, exposing systems to significant risk. The details of this vulnerability have been made publicly available, heightening concerns for users of My-Blog 1.0. Immediate action should be taken to mitigate this risk.
Affected Version(s)
My-Blog 1.0
References
CVSS V4
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Credit
LVZC1 (VulDB User)