Unrated severityNVD Advisory· Published Jan 5, 2025· Updated Jan 6, 2025
ZeroWdd studentmanager StudentController. java editStudent unrestricted upload
CVE-2024-13133
Description
A vulnerability, which was classified as critical, has been found in ZeroWdd studentmanager 1.0. This issue affects the function addStudent/editStudent of the file src/main/Java/com/wdd/studentmanager/controller/StudentController. java. The manipulation of the argument file leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected products
1- Range: 1.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- github.com/ZeroWdd/studentmanager/issues/16mitreexploitissue-tracking
- github.com/ZeroWdd/studentmanager/issues/16mitreissue-tracking
- vuldb.commitresignaturepermissions-required
- vuldb.commitrevdb-entrytechnical-description
News mentions
0No linked articles in our index yet.