Unrated severityNVD Advisory· Published Jan 5, 2025· Updated Jan 6, 2025
wangl1989 mysiteforme ShiroConfig.java rememberMeManager deserialization
CVE-2024-13136
Description
A vulnerability was found in wangl1989 mysiteforme 1.0 and classified as critical. Affected by this issue is the function rememberMeManager of the file src/main/java/com/mysiteforme/admin/config/ShiroConfig.java. The manipulation leads to deserialization. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Affected products
1- Range: 1.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- github.com/wangl1989/mysiteforme/issues/52mitreexploitissue-tracking
- vuldb.commitrethird-party-advisory
- github.com/wangl1989/mysiteforme/issues/52mitreissue-tracking
- vuldb.commitresignaturepermissions-required
- vuldb.commitrevdb-entrytechnical-description
News mentions
0No linked articles in our index yet.