WisdomGarden Tronclass - Broken Access Control
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 5.3epss 0.5%
exploitation probability
0.5%top 63% of all CVEs
observed exploitation
nono source reports it
The tumbnail API of Tronclass from WisdomGarden lacks proper access control, allowing unauthenticated remote attackers to obtain certain specific files by modifying the URL.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Affected products
WisdomGarden · Tronclass