Metrics
Affected Vendors & Products
Wed, 25 Sep 2024 17:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Jflow Project
Jflow Project jflow |
|
Weaknesses | NVD-CWE-Other | |
CPEs | cpe:2.3:a:jflow_project:jflow:2.0.0:*:*:*:*:*:*:* | |
Vendors & Products |
Jflow Project
Jflow Project jflow |
Fri, 20 Sep 2024 14:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Jinan Chicheng Company
Jinan Chicheng Company jflow |
|
CPEs | cpe:2.3:a:jinan_chicheng_company:jflow:2.0.0:*:*:*:*:*:*:* | |
Vendors & Products |
Jinan Chicheng Company
Jinan Chicheng Company jflow |
|
Metrics |
ssvc
|
Thu, 19 Sep 2024 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability was found in Jinan Chicheng Company JFlow 2.0.0. It has been rated as problematic. This issue affects the function AttachmentUploadController of the file /WF/Ath/EntityMutliFile_Load.do of the component Attachment Handler. The manipulation of the argument oid leads to improper access controls. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | |
Title | Jinan Chicheng Company JFlow Attachment EntityMutliFile_Load.do AttachmentUploadController access control | |
Weaknesses | CWE-284 | |
References |
| |
Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2024-09-19T21:00:07.682Z
Updated: 2024-09-20T13:50:49.213Z
Reserved: 2024-09-19T14:27:40.564Z
Link: CVE-2024-9003
Updated: 2024-09-20T13:50:43.226Z
Status : Analyzed
Published: 2024-09-19T21:15:16.143
Modified: 2024-09-25T17:18:44.523
Link: CVE-2024-9003
No data.