A
vulnerability classified as problematic has been found in Beijing Yunfan Internet Technology Yunfan Learning Examination System 1.9.2. Affected is an unknown function of the file src/main/java/com/yf/exam/modules/paper/controller/PaperController.java, of the component Exam Answer Handler. The manipulation leads to information disclosure. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
References
| Link | Resource |
|---|---|
| https://github.com/qiutiandefeng/yfexam-exam/issues/5 | Exploit Issue Tracking |
| https://github.com/qiutiandefeng/yfexam-exam/issues/5#issue-2754675223 | Exploit Issue Tracking |
| https://vuldb.com/?ctiid.289926 | Permissions Required VDB Entry |
| https://vuldb.com/?id.289926 | Third Party Advisory VDB Entry |
| https://vuldb.com/?submit.467700 | Third Party Advisory VDB Entry |
Configurations
History
25 Aug 2025, 17:14
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | NVD-CWE-noinfo | |
| CPE | cpe:2.3:a:kaoshifeng:yunfan_learning_examination_system:1.9.2:*:*:*:*:*:*:* | |
| First Time |
Kaoshifeng
Kaoshifeng yunfan Learning Examination System |
|
| References | () https://github.com/qiutiandefeng/yfexam-exam/issues/5 - Exploit, Issue Tracking | |
| References | () https://github.com/qiutiandefeng/yfexam-exam/issues/5#issue-2754675223 - Exploit, Issue Tracking | |
| References | () https://vuldb.com/?ctiid.289926 - Permissions Required, VDB Entry | |
| References | () https://vuldb.com/?id.289926 - Third Party Advisory, VDB Entry | |
| References | () https://vuldb.com/?submit.467700 - Third Party Advisory, VDB Entry | |
| Summary |
|
02 Jan 2025, 14:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-01-02 14:15
Updated : 2025-08-25 17:14
NVD link : CVE-2024-13110
Mitre link : CVE-2024-13110
CVE.ORG link : CVE-2024-13110
JSON object : View
Products Affected
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
CWE-284Improper Access Control
NVD-CWE-noinfo