Vulnerability in JFlow 2.0.0 Could Allow Remote Access Controls
CVE-2024-9003

5.3MEDIUM

Key Information:

Status
Vendor
CVE Published:
19 September 2024

Badges

👾 Exploit Exists

What is CVE-2024-9003?

A vulnerability exists in Jinan Chicheng Company's JFlow version 2.0.0, specifically within the AttachmentUploadController of the file /WF/Ath/EntityMutliFile_Load.do. This vulnerability allows for improper access controls due to arguments manipulation, which may lead to unauthorized access. The exploit can be initiated remotely, making this issue particularly concerning as it exposes sensitive functionalities within the application. The vendor had been notified about this issue but did not respond, indicating a need for user awareness and potential mitigation strategies.

Affected Version(s)

JFlow 2.0.0

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

hexixi (VulDB User)
.