← back
CVE-2024-13212

SingMR HouseRent AddHouseController.java upload unrestricted upload

CVSS 5.3 MEDIUMEPSS 0.4%CWE-284CWE-434
A vulnerability classified as critical has been found in SingMR HouseRent 1.0. This affects the function singleUpload/upload of the file src/main/java/com/house/wym/controller/AddHouseController.java. The manipulation of the argument file leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
Affected products
SingMR · HouseRent

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →