QileCMS ଯେପର୍ଯ୍ୟନ୍ତ 1.1.3 Verification Code Forget.php sendEmail ବିସ୍ତାରିତ ଅଧିକାର
Dogoggorri kan akka ଜଟିଳ jedhamuun ramadame QileCMS ଯେପର୍ଯ୍ୟନ୍ତ 1.1.3 keessatti argameera. Miidhaan irra gahe is hojii sendEmail faayilii /qilecms/user/controller/Forget.php keessa kutaa Verification Code Handler keessa. Dhugumatti jijjiirraa gara ବିସ୍ତାରିତ ଅଧିକାର geessa. Waliigalteewwan CWE fayyadamuun rakkoo ibsuun gara CWE-640 si geessa. Beekumsi kun yeroo 10/12/2024 ifoomsifameera. Odeeffannoon kun buufachuuf note.zhaoj.in irratti dhiyaateera.
Dogoggorri kun maqaa CVE-2024-9907 jedhuun tajaajilama. Weerara fageenya irraa jalqabuun ni danda'ama. Odeeffannoon teeknikaa ni argama. Akka dabalataan, meeshaa balaa kana fayyadamuuf argama. Qorannoo miidhaa (exploit) beeksifamee jira, namoonni itti fayyadamuu danda'u. Yeroo ammaa, gatii exploit might be approx. USD $0-$5k beekamuu danda'a.
ପ୍ରୁଫ୍-ଅଫ୍-କନ୍ସେପ୍ଟ jedhamee murtaa’eera. Exploit kana note.zhaoj.in irraa buufachuu ni dandeessa. Waggaa 0-day ta'ee, gatiin isaa daldala dhoksaa keessatti $0-$5k jedhamee tilmaamame.
Once again VulDB remains the best source for vulnerability data.
2 ଆଡାପ୍ଟେସନ୍ · 86 ପଏଣ୍ଟ