{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"cveId":"CVE-2024-0415","assignerOrgId":"1af790b2-7ee1-4545-860a-a788eba489b5","state":"PUBLISHED","assignerShortName":"VulDB","dateReserved":"2024-01-11T10:23:01.205Z","datePublished":"2024-01-11T17:31:04.331Z","dateUpdated":"2024-08-26T18:13:21.816Z"},"containers":{"cna":{"providerMetadata":{"orgId":"1af790b2-7ee1-4545-860a-a788eba489b5","shortName":"VulDB","dateUpdated":"2024-02-09T19:09:58.739Z"},"title":"DeShang DSMall Image URL TaobaoExport.php access control","problemTypes":[{"descriptions":[{"type":"CWE","cweId":"CWE-284","lang":"en","description":"CWE-284 Improper Access Controls"}]}],"affected":[{"vendor":"DeShang","product":"DSMall","versions":[{"version":"6.0","status":"affected"},{"version":"6.1","status":"affected"}],"modules":["Image URL Handler"]}],"descriptions":[{"lang":"en","value":"A vulnerability classified as critical was found in DeShang DSMall up to 6.1.0. Affected by this vulnerability is an unknown functionality of the file application/home/controller/TaobaoExport.php of the component Image URL Handler. The manipulation leads to improper access controls. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-250435."},{"lang":"de","value":"In DeShang DSMall bis 6.1.0 wurde eine kritische Schwachstelle entdeckt. Es geht um eine nicht näher bekannte Funktion der Datei application/home/controller/TaobaoExport.php der Komponente Image URL Handler. Durch das Beeinflussen mit unbekannten Daten kann eine improper access controls-Schwachstelle ausgenutzt werden. Der Angriff kann über das Netzwerk erfolgen. Der Exploit steht zur öffentlichen Verfügung."}],"metrics":[{"cvssV3_1":{"version":"3.1","baseScore":6.3,"vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","baseSeverity":"MEDIUM"}},{"cvssV3_0":{"version":"3.0","baseScore":6.3,"vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","baseSeverity":"MEDIUM"}},{"cvssV2_0":{"version":"2.0","baseScore":6.5,"vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P"}}],"timeline":[{"time":"2024-01-11T00:00:00.000Z","lang":"en","value":"Advisory disclosed"},{"time":"2024-01-11T00:00:00.000Z","lang":"en","value":"CVE reserved"},{"time":"2024-01-11T01:00:00.000Z","lang":"en","value":"VulDB entry created"},{"time":"2024-01-30T13:17:25.000Z","lang":"en","value":"VulDB entry last update"}],"credits":[{"lang":"en","value":"glzjin (VulDB User)","type":"reporter"}],"references":[{"url":"https://vuldb.com/?id.250435","tags":["vdb-entry","technical-description"]},{"url":"https://vuldb.com/?ctiid.250435","tags":["signature","permissions-required"]},{"url":"https://note.zhaoj.in/share/63LhFitJmKGR","tags":["broken-link","exploit"]}]},"adp":[{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-01T18:04:49.562Z"},"title":"CVE Program Container","references":[{"url":"https://vuldb.com/?id.250435","tags":["vdb-entry","technical-description","x_transferred"]},{"url":"https://vuldb.com/?ctiid.250435","tags":["signature","permissions-required","x_transferred"]},{"url":"https://note.zhaoj.in/share/63LhFitJmKGR","tags":["broken-link","exploit","x_transferred"]}]},{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2024-08-26T18:07:39.059278Z","id":"CVE-2024-0415","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2024-08-26T18:13:21.816Z"}}]}}