CVE-2024-13195
CVSS 3.1 Score 6.3 of 10 (medium)
Details
Published Jan 9, 2025
CWE ID 918
Summary
CVE-2024-13195 is a critical vulnerability that affects the donglight bookstore电商书城系统说明 1.0.0. The issue lies in the getHtml function of the HttpUtil.java file. Manipulation of the url argument can lead to server-side request forgery, enabling attackers to initiate unauthorized requests. This vulnerability has been publicly disclosed, increasing the risk of remote exploitation.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.