CVE-2024-13138
CVSS 3.1 Score 8.8 of 10 (high)
Details
Published Jan 5, 2025
Updated: Jan 10, 2025
CWE ID 434
CWE ID 284
Summary
CVE-2024-13138 is a critical vulnerability affecting the wangl1989 mysiteforme 1.0 software. The issue lies in the LocalUploadServiceImpl class within the src/main/java/com/mysiteform/admin/service/ipl/ directory. An attacker can manipulate the 'test' argument in the upload function, resulting in unrestricted file upload. This vulnerability is remotely exploitable, and the exploit has been disclosed to the public. Systems running this version of mysiteforme are at risk and should be immediately patched.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Mysiteforme
Affected Vendors
- Mysiteforme