ZeroHour

CVE-2024-6738

CVSS 3.1
5.3 medium
EPSS
<1%p38
Published
()
Modified
Description

The tumbnail API of Tronclass from WisdomGarden lacks proper access control, allowing unauthenticated remote attackers to obtain certain specific files by modifying the URL.

Vendors
wisdomgarden
Products
tronclass
Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.