CVE-2024-13195

CVSS 3.1 Score 6.3 of 10 (medium)

Details

Published Jan 9, 2025
CWE ID 918

Summary

CVE-2024-13195 is a critical vulnerability that affects the donglight bookstore电商书城系统说明 1.0.0. The issue lies in the getHtml function of the HttpUtil.java file. Manipulation of the url argument can lead to server-side request forgery, enabling attackers to initiate unauthorized requests. This vulnerability has been publicly disclosed, increasing the risk of remote exploitation.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share