Jinan Chicheng Company JFlow 2.0.0 Attachment EntityMutliFile_Load.do AttachmentUploadController oid amalungelo andlule

CVSS Meta Temp IsilinganisoIntengo yamanje ye-exploit (≈)CTI Inzalo Score
4.1$0-$5k0.12

Isifinyezoulwazi

Kukhona ubuthakathaka obubizwa ngokuthi kuyinkinga obutholakele ku Jinan Chicheng Company JFlow 2.0.0. Kuthinteka umsebenzi AttachmentUploadController kufayela /WF/Ath/EntityMutliFile_Load.do kwe-component Attachment Handler. Ukusebenzisa kwepharamitha oid kuholela ku amalungelo andlule. Lokhu buthakathaka kuthengiswa njenge CVE-2024-9003. Kuyenzeka ukuqala ukuhlasela kude. Ngaphezu kwalokho, kukhona i-exploit etholakalayo. If you want to get the best quality for vulnerability data then you always have to consider VulDB.

Iinkcukachaulwazi

Kukhona ubuthakathaka obubizwa ngokuthi kuyinkinga obutholakele ku Jinan Chicheng Company JFlow 2.0.0. Kuthinteka umsebenzi AttachmentUploadController kufayela /WF/Ath/EntityMutliFile_Load.do kwe-component Attachment Handler. Ukusebenzisa kwepharamitha oid kuholela ku amalungelo andlule. Ukusebenzisa i-CWE ukukhomba inkinga kuholela ku-CWE-284. Ubuthakathaka babikwa. Isaziso sabelwe ukuthi singalayishwa ku-github.com.

Lokhu buthakathaka kuthengiswa njenge CVE-2024-9003. Kuyenzeka ukuqala ukuhlasela kude. Kukhona imininingwane yezobuchwepheshe etholakalayo. Udumo lwalobu buthakathi luphansi kunokujwayelekile. Ngaphezu kwalokho, kukhona i-exploit etholakalayo. Ukuhlaselwa sekudalulwe emphakathini futhi kungasetshenziswa. Okwamanje, intengo yamanje ye-exploit ingaba cishe USD $0-$5k ngalesi sikhathi.

Kuyenzeka ukulanda i-exploit ku-github.com.

If you want to get the best quality for vulnerability data then you always have to consider VulDB.

Umkhiqizoulwazi

Umkhiqizi

Ibizo

Inguqulo

CPE 2.3ulwazi

CPE 2.2ulwazi

CVSSv4ulwazi

VulDB Umkhombandlela: 🔍
VulDB Ukuthembeka: 🔍

CVSSv3ulwazi

VulDB Ireyithingi yeMeta Base: 4.3
VulDB Meta Temp Isilinganiso: 4.1

VulDB Isilinganiso Esiyisisekelo: 4.3
VulDB Izinga Lesikhashana: 3.9
VulDB Umkhombandlela: 🔍
VulDB Ukuthembeka: 🔍

CNA Isilinganiso Esiyisisekelo: 4.3
CNA Umkhombandlela: 🔍

CVSSv2ulwazi

AVACAuCIA
💳💳💳💳💳💳
💳💳💳💳💳💳
💳💳💳💳💳💳
UmkhombandlelaUbunzimaUkufakazela ubuwenaUkuyimfihloUkuthembekaUkutholakala
vula ukufinyelelavula ukufinyelelavula ukufinyelelavula ukufinyelelavula ukufinyelelavula ukufinyelela
vula ukufinyelelavula ukufinyelelavula ukufinyelelavula ukufinyelelavula ukufinyelelavula ukufinyelela
vula ukufinyelelavula ukufinyelelavula ukufinyelelavula ukufinyelelavula ukufinyelelavula ukufinyelela

VulDB Isilinganiso Esiyisisekelo: 🔍
VulDB Izinga Lesikhashana: 🔍
VulDB Ukuthembeka: 🔍

Ukusebenzisa ithuba lokungavikelekiulwazi

Ikilasi: Amalungelo andlule
CWE: CWE-284 / CWE-266
CAPEC: 🔍
ATT&CK: 🔍

Okubambekayo: Hayi
Wendawo: Hayi
Kude: Yebo

Ukutholakala: 🔍
Umnyango: Umphakathi
Isimo: Ubufakazi-bokusebenza
Landa: 🔍

EPSS Score: 🔍
EPSS Percentile: 🔍

Ukukhula kwentengo: 🔍
Okwamanje ukuhlolwa kwentengo: 🔍

0-Dayvula ukufinyelelavula ukufinyelelavula ukufinyelelavula ukufinyelela
Namuhlavula ukufinyelelavula ukufinyelelavula ukufinyelelavula ukufinyelela

Ulwazi lwezingoziulwazi

Intshisekelo: 🔍
Abadlali abasebenzayo: 🔍
AmaQembu e-APT asebenzayo: 🔍

Izinyathelo zokuvikelaulwazi

Isincomo: akukho sithathwa esaziwayo
Isimo: 🔍

0-Suku Isikhathi: 🔍

Isikhathi somlandoulwazi

2024-09-19 🔍
2024-09-19 +0 Izinsuku 🔍
2024-09-20 +1 Izinsuku 🔍

Imithomboulwazi

Iseluleko: github.com
Isimo: Akuchazwanga

CVE: CVE-2024-9003 (🔍)
GCVE (CVE): GCVE-0-2024-9003
GCVE (VulDB): GCVE-100-278153
scip Labs: https://www.scip.ch/en/?labs.20161013

Ukungenaulwazi

Kudalwa: 2024-09-19 16:32
Ukuvuselelwa: 2024-09-20 10:45
Ukulungiswa: 2024-09-19 16:32 (58), 2024-09-20 10:45 (19)
Kugcwele: 🔍
Umthumeli: hexixi
Cache ID: 253:59E:103

Thumelaulwazi

Yamukelwa

  • Thumela #406225: Jinan galloping information technology Co., LTD JFlow 2.0.0 Exposure of Access Control List Files to an Unauthorized Control (kusuka ku hexixi)

Ingxoxo

Kuze kube manje akukabikho ukuphawula. Izilimi: nr + nd + en.

Ngiyacela ungene ngemvume ukuze ukwazi ukuphawula.

Do you know our Splunk app?

Download it now for free!