CVE-2024-13110

A

vulnerability classified as problematic has been found in Beijing Yunfan Internet Technology Yunfan Learning Examination System 1.9.2. Affected is an unknown function of the file src/main/java/com/yf/exam/modules/paper/controller/PaperController.java, of the component Exam Answer Handler. The manipulation leads to information disclosure. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

References
Link Resource
https://github.com/qiutiandefeng/yfexam-exam/issues/5 Exploit Issue Tracking
https://github.com/qiutiandefeng/yfexam-exam/issues/5#issue-2754675223 Exploit Issue Tracking
https://vuldb.com/?ctiid.289926 Permissions Required VDB Entry
https://vuldb.com/?id.289926 Third Party Advisory VDB Entry
https://vuldb.com/?submit.467700 Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

cpe:2.3:a:kaoshifeng:yunfan_learning_examination_system:1.9.2:*:*:*:*:*:*:*

History

25 Aug 2025, 17:14

Type Values Removed Values Added
CWE NVD-CWE-noinfo
CPE cpe:2.3:a:kaoshifeng:yunfan_learning_examination_system:1.9.2:*:*:*:*:*:*:*
First Time Kaoshifeng
Kaoshifeng yunfan Learning Examination System
References () https://github.com/qiutiandefeng/yfexam-exam/issues/5 - () https://github.com/qiutiandefeng/yfexam-exam/issues/5 - Exploit, Issue Tracking
References () https://github.com/qiutiandefeng/yfexam-exam/issues/5#issue-2754675223 - () https://github.com/qiutiandefeng/yfexam-exam/issues/5#issue-2754675223 - Exploit, Issue Tracking
References () https://vuldb.com/?ctiid.289926 - () https://vuldb.com/?ctiid.289926 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.289926 - () https://vuldb.com/?id.289926 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.467700 - () https://vuldb.com/?submit.467700 - Third Party Advisory, VDB Entry
Summary
  • (es) Se ha encontrado una vulnerabilidad clasificada como problemática en Beijing Yunfan Internet Technology Yunfan Learning Examination System 1.9.2. Se ve afectada una función desconocida del archivo src/main/java/com/yf/exam/modules/paper/controller/PaperController.java ?del componente Exam Answer Handler. La manipulación conduce a la divulgación de información. Es posibleLanzar el ataque de forma remota. El exploit se ha hecho público y puede utilizarse.

02 Jan 2025, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-02 14:15

Updated : 2025-08-25 17:14


NVD link : CVE-2024-13110

Mitre link : CVE-2024-13110

CVE.ORG link : CVE-2024-13110


JSON object : View

CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

CWE-284

Improper Access Control

NVD-CWE-noinfo