Vulnerability in JFlow 2.0.0 Could Allow Remote Access Controls
CVE-2024-9003
5.3MEDIUM
Key Information:
- Vendor
Jinan Chicheng Company
- Status
- Vendor
- CVE Published:
- 19 September 2024
Badges
👾 Exploit Exists
What is CVE-2024-9003?
A vulnerability exists in Jinan Chicheng Company's JFlow version 2.0.0, specifically within the AttachmentUploadController of the file /WF/Ath/EntityMutliFile_Load.do. This vulnerability allows for improper access controls due to arguments manipulation, which may lead to unauthorized access. The exploit can be initiated remotely, making this issue particularly concerning as it exposes sensitive functionalities within the application. The vendor had been notified about this issue but did not respond, indicating a need for user awareness and potential mitigation strategies.
Affected Version(s)
JFlow 2.0.0
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved
Credit
hexixi (VulDB User)
