First published: Sun Jan 05 2025(Updated: )
A vulnerability, which was classified as critical, has been found in ZeroWdd studentmanager 1.0. This issue affects the function addStudent/editStudent of the file src/main/Java/com/wdd/studentmanager/controller/StudentController. java. The manipulation of the argument file leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
student-manage |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-13133 is classified as a critical vulnerability.
To fix CVE-2024-13133, update the ZeroWdd studentmanager application to the latest version that addresses this issue.
CVE-2024-13133 affects the addStudent/editStudent functions in the StudentController.java file of the ZeroWdd studentmanager software.
CVE-2024-13133 is a manipulation vulnerability affecting the file argument in the student management functionality.
The vendor for CVE-2024-13133 is ZeroWdd, which develops the studentmanager software.