VYPR
Medium severity6.5NVD Advisory· Published Mar 27, 2023· Updated Jun 17, 2026

CVE-2023-24834

CVE-2023-24834

Description

WisdomGarden Tronclass has improper access control when uploading file. An authenticated remote attacker with general user privilege can exploit this vulnerability to access files belonging to other users by modifying the file ID within URL.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

5
  • cpe:2.3:a:wisdomgarden:tronclass_ilearn:*:*:*:*:web:*:*:*+ 2 more
    • cpe:2.3:a:wisdomgarden:tronclass_ilearn:*:*:*:*:web:*:*:*range: <1.52.29198
    • cpe:2.3:a:wisdomgarden:tronclass_ilearn:2.3.2:*:*:*:*:android:*:*
    • cpe:2.3:a:wisdomgarden:tronclass_ilearn:2.3.2:*:*:*:*:iphone_os:*:*
  • WisdomGarden/Tronclassllm-fuzzy2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: 2.3.2

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.