CVE-2024-11961

A vulnerability was found in Guangzhou Huayi Intelligent Technology Jeewms 3.7. It has been rated as problematic. This issue affects the function preHandle of the file src/main/java/com/zzjee/wm/controller/WmOmNoticeHController.java. The manipulation of the argument request leads to information disclosure. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:huayi-tec:jeewms:3.7:*:*:*:*:*:*:*

History

11 Dec 2024, 19:59

Type Values Removed Values Added
References () https://github.com/dycccccccc/JEEWMS/blob/main/JEEWMS%20Shipper%20Information%20Leakage.docx - () https://github.com/dycccccccc/JEEWMS/blob/main/JEEWMS%20Shipper%20Information%20Leakage.docx - Exploit, Third Party Advisory
References () https://vuldb.com/?ctiid.286343 - () https://vuldb.com/?ctiid.286343 - Permissions Required
References () https://vuldb.com/?id.286343 - () https://vuldb.com/?id.286343 - Third Party Advisory
References () https://vuldb.com/?submit.445596 - () https://vuldb.com/?submit.445596 - Third Party Advisory
CPE cpe:2.3:a:huayi-tec:jeewms:3.7:*:*:*:*:*:*:*
Summary
  • (es) Se encontró una vulnerabilidad en Guangzhou Huayi Intelligent Technology Jeewms 3.7. Se la ha calificado como problemática. Este problema afecta a la función preHandle del archivo src/main/java/com/zzjee/wm/controller/WmOmNoticeHController.java. La manipulación de la solicitud de argumentos conduce a la divulgación de información. El ataque puede iniciarse de forma remota. La vulnerabilidad se ha divulgado al público y puede utilizarse. Se contactó al proveedor con anticipación sobre esta divulgación, pero no respondió de ninguna manera.
First Time Huayi-tec
Huayi-tec jeewms
CWE NVD-CWE-noinfo

28 Nov 2024, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-28 15:15

Updated : 2024-12-11 19:59


NVD link : CVE-2024-11961

Mitre link : CVE-2024-11961

CVE.ORG link : CVE-2024-11961


JSON object : View

Products Affected

huayi-tec

  • jeewms
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

CWE-284

Improper Access Control

NVD-CWE-noinfo