Description


A vulnerability, which was classified as critical, was found in HuangDou UTCMS V9. This affects an unknown part of the file app/modules/ut-template/admin/template_creat.php. The manipulation of the argument content leads to deserialization. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Related CPE's


References



https://vuldb.com/?ctiid.280245

Permissions RequiredThird Party AdvisoryVDB Entry

https://vuldb.com/?id.280245

Third Party AdvisoryVDB Entry

https://vuldb.com/?submit.418749

Third Party AdvisoryVDB Entry

Weaknesses



CWE-502

CVSS impact metrics


CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

6.3 · Medium

Information


Source identifier

[email protected]

Vulnerability status

Analyzed

Published

2024-10-13T18:15:03.593Z

1 year ago

Last modified

2024-10-18T22:49:07.090Z

1 year ago