CVE-2024-13110

MEDIUM

Yunfan Learning Examination System 1.9.2 - Information Disclosure in Exam Answer Handler

Title source: llm
STIX 2.1

Description

A vulnerability classified as problematic has been found in Beijing Yunfan Internet Technology Yunfan Learning Examination System 1.9.2. Affected is an unknown function of the file src/main/java/com/yf/exam/modules/paper/controller/PaperController.java, of the component Exam Answer Handler. The manipulation leads to information disclosure. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry
https://vuldb.com/?id.289926
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.289926
Third Party Advisory, VDB Entry third-party-advisory
https://vuldb.com/?submit.467700
Exploit, Issue Tracking issue-tracking
https://github.com/qiutiandefeng/yfexam-exam/issues/5
Exploit, Issue Tracking exploit issue-tracking
https://github.com/qiutiandefeng/yfexam-exam/issues/5#issue-2754675223

Scores

CVSS v3 4.3
EPSS 0.0059
EPSS Percentile 43.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-200 CWE-284
Status published
Products (1)
kaoshifeng/yunfan_learning_examination_system 1.9.2
Published Jan 02, 2025
Tracked Since Feb 18, 2026