A vulnerability classified as problematic has been found in Beijing Yunfan Internet Technology Yunfan Learning Examination System 1.9.2. Affected is an unknown function of the file src/main/java/com/yf/exam/modules/paper/controller/PaperController.java, of the component Exam Answer Handler. The manipulation leads to information disclosure. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
References
| Link | Resource |
|---|---|
| https://github.com/qiutiandefeng/yfexam-exam/issues/5 | Exploit Issue Tracking |
| https://github.com/qiutiandefeng/yfexam-exam/issues/5#issue-2754675223 | Exploit Issue Tracking |
| https://vuldb.com/?ctiid.289926 | Permissions Required VDB Entry |
| https://vuldb.com/?id.289926 | Third Party Advisory VDB Entry |
| https://vuldb.com/?submit.467700 | Third Party Advisory VDB Entry |
Configurations
History
No history.
Information
Published : 2025-01-02 14:15
Updated : 2025-08-25 17:14
NVD link : CVE-2024-13110
Mitre link : CVE-2024-13110
CVE.ORG link : CVE-2024-13110
JSON object : View
Products Affected
kaoshifeng
- yunfan_learning_examination_system
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
CWE-284Improper Access Control
NVD-CWE-noinfo