5.3
CVE-2024-6738
- EPSS 0.13%
- Veröffentlicht 15.07.2024 03:15:03
- Zuletzt bearbeitet 21.11.2024 09:50:13
- Quelle twcert@cert.org.tw
- CVE-Watchlists
- Unerledigt
The tumbnail API of Tronclass from WisdomGarden lacks proper access control, allowing unauthenticated remote attackers to obtain certain specific files by modifying the URL.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Wisdomgarden ≫ Tronclass Version < 1.69.61976
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.13% | 0.325 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| twcert@cert.org.tw | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
|
CWE-284 Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.