Unrestricted File Upload Vulnerability in ZeroWdd myblog Software
CVE-2024-13191
9.8CRITICAL
What is CVE-2024-13191?
A vulnerability affecting ZeroWdd myblog 1.0 allows for unrestricted file uploads through the upload function in the uploadController.java file. Attackers can manipulate file upload parameters to initiate remote attacks, potentially leading to server compromise. The exploit has been publicly disclosed, raising concerns over the potential for unauthorized access and malicious file execution. Users are advised to apply security measures immediately to mitigate risks.