Vulnerability in JFlow 2.0.0 Could Allow Remote Access Controls
CVE-2024-9003
Key Information:
- Vendor
- Jinan Chicheng Company
- Status
- Jflow
- Vendor
- CVE Published:
- 19 September 2024
Badges
Summary
A vulnerability exists in Jinan Chicheng Company's JFlow version 2.0.0, specifically within the AttachmentUploadController of the file /WF/Ath/EntityMutliFile_Load.do. This vulnerability allows for improper access controls due to arguments manipulation, which may lead to unauthorized access. The exploit can be initiated remotely, making this issue particularly concerning as it exposes sensitive functionalities within the application. The vendor had been notified about this issue but did not respond, indicating a need for user awareness and potential mitigation strategies.
Affected Version(s)
JFlow 2.0.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- π‘
Public PoC available
- πΎ
Exploit known to exist
Vulnerability published
Vulnerability Reserved