CVE-2024-13042 Information

Description

A vulnerability was found in Tsinghua Unigroup Electronic Archives Management System 3.2.210802(62532). It has been classified as problematic. Affected is the function download of the file SubjectController.class.php. The manipulation of the argument path leads to information disclosure. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

Reference

https://github.com/BxYQ/zg_fileread https://github.com/BxYQ/zg_fileread/blob/main/poc.py https://vuldb.com/?ctiid.289788 https://vuldb.com/?id.289788 https://vuldb.com/?submit.472068

Share on: