CVE-2024-12483

LOW

Dromara UJCMS <= 9.6.3 - Authorization Bypass in User ID Handler

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2024-12483. PoCs published by Cyd Tseng.

AI-analyzed exploit summary This exploit demonstrates an IDOR vulnerability in UJCMS 9.6.3, allowing unauthenticated enumeration of usernames by manipulating the user ID parameter in the /users/id endpoint. It systematically checks for valid user IDs and extracts usernames from the response.

Description

A vulnerability classified as problematic has been found in Dromara UJCMS up to 9.6.3. This affects an unknown part of the file /users/id of the component User ID Handler. The manipulation leads to authorization bypass. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used.

Exploits (1)

exploitdb WORKING POC
by Cyd Tseng · pythonwebappsmultiple
https://www.exploit-db.com/exploits/52264

This exploit demonstrates an IDOR vulnerability in UJCMS 9.6.3, allowing unauthenticated enumeration of usernames by manipulating the user ID parameter in the /users/id endpoint. It systematically checks for valid user IDs and extracts usernames from the response.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: UJCMS 9.6.3
No auth needed
Prerequisites: Network access to the target UJCMS instance
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry
https://vuldb.com/?id.287865
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.287865
Third Party Advisory, VDB Entry third-party-advisory
https://vuldb.com/?submit.458895

Scores

CVSS v3 3.7
EPSS 0.0344
EPSS Percentile 87.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-285 CWE-639
Status published
Products (1)
ujcms/ujcms < 9.6.3
Published Dec 12, 2024
Tracked Since Feb 18, 2026