Unrestricted File Upload in Donglight Bookstore System 1.0
CVE-2024-13210
Key Information:
- Vendor
- Donglight
- Status
- Bookstore电商书城系统说明
- Vendor
- CVE Published:
- 9 January 2025
Badges
Summary
A vulnerability has been identified in Donglight Bookstore System 1.0, specifically in the uploadPicture function of the AdminBookController located in src/main/java/org/zdd/bookstore/web/controller/admin. An attacker can exploit this flaw to perform unrestricted file uploads, which may lead to further attacks, including remote code execution. This vulnerability poses significant security risks as it allows malicious users to upload arbitrary files, potentially compromising the system integrity. The possibility of remote exploitation makes this issue urgent and necessitates a prompt response from users to mitigate risks.
Affected Version(s)
bookstore电商书城系统说明 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved