Vulnerability in JFlow 2.0.0 Could Allow Remote Access Controls
CVE-2024-9003
5.3MEDIUM
Key Information:
- Vendor
Jinan Chicheng Company
- Status
- Vendor
- CVE Published:
- 19 September 2024
Badges
👾 Exploit Exists
What is CVE-2024-9003?
A vulnerability exists in Jinan Chicheng Company's JFlow version 2.0.0, specifically within the AttachmentUploadController of the file /WF/Ath/EntityMutliFile_Load.do. This vulnerability allows for improper access controls due to arguments manipulation, which may lead to unauthorized access. The exploit can be initiated remotely, making this issue particularly concerning as it exposes sensitive functionalities within the application. The vendor had been notified about this issue but did not respond, indicating a need for user awareness and potential mitigation strategies.
Affected Version(s)
JFlow 2.0.0