CVE-2024-13110

A vulnerability classified as problematic has been found in Beijing Yunfan Internet Technology Yunfan Learning Examination System 1.9.2. Affected is an unknown function of the file src/main/java/com/yf/exam/modules/paper/controller/PaperController.java, of the component Exam Answer Handler. The manipulation leads to information disclosure. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
References
Link Resource
https://github.com/qiutiandefeng/yfexam-exam/issues/5 Exploit Issue Tracking
https://github.com/qiutiandefeng/yfexam-exam/issues/5#issue-2754675223 Exploit Issue Tracking
https://vuldb.com/?ctiid.289926 Permissions Required VDB Entry
https://vuldb.com/?id.289926 Third Party Advisory VDB Entry
https://vuldb.com/?submit.467700 Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

cpe:2.3:a:kaoshifeng:yunfan_learning_examination_system:1.9.2:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-01-02 14:15

Updated : 2025-08-25 17:14


NVD link : CVE-2024-13110

Mitre link : CVE-2024-13110

CVE.ORG link : CVE-2024-13110


JSON object : View

Products Affected

kaoshifeng

  • yunfan_learning_examination_system
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

CWE-284

Improper Access Control

NVD-CWE-noinfo