SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2023-24834

WisdomGarden Tronclass has improper access control when uploading file.

MEDIUM 6.5EPSS 0.64%

Does this matter?

Lower severity and a low EPSS score (0.64%). Track it; it rarely justifies an emergency change on its own.

Description

WisdomGarden Tronclass has improper access control when uploading file. An authenticated remote attacker with general user privilege can exploit this vulnerability to access files belonging to other users by modifying the file ID within URL.

CVSS 3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS
0.64% probability · 49th percentile
CISA KEV
Not listed
Weakness
CWE-639
Affected
wisdomgarden/tronclass ilearn
Source
twcert@cert.org.tw

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.