CVE-2024-2828
Last modified
CVE-2024-2828 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. A vulnerability, which was classified as critical, was found in lakernote EasyAdmin up to 20240315. Affected is the function thumbnail of the file src/main/java/com/laker/admin/module/sys/controller/IndexController.java. EPSS estimates a 0.56% chance of exploitation in the next 30 days.
Description
A vulnerability, which was classified as critical, was found in lakernote EasyAdmin up to 20240315. Affected is the function thumbnail of the file src/main/java/com/laker/admin/module/sys/controller/IndexController.java. The manipulation of the argument url leads to server-side request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The patch is identified as 23165d8cb569048c531150f194fea39f8800b8d5. It is recommended to apply a patch to fix this issue. VDB-257718 is the identifier assigned to this vulnerability.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Lakernote | Easyadmin | <= 2024-03-15 |
References
- https://gitee.com/lakernote/easy-admin/issues/I98YSRExploit, Issue Tracking
- https://vuldb.com/?ctiid.257718Permissions Required, VDB Entry
- https://vuldb.com/?id.257718Third Party Advisory, VDB Entry
- https://gitee.com/lakernote/easy-admin/issues/I98YSRExploit, Issue Tracking
- https://vuldb.com/?ctiid.257718Permissions Required, VDB Entry
- https://vuldb.com/?id.257718Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-2828?
How severe is CVE-2024-2828?
How do I fix CVE-2024-2828?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-2827A vulnerability, which was classified as critical, has been …8.8
- CVE-2024-28270An issue discovered in web-flash v3.0 allows attackers to re…8.1
- CVE-2024-28275Puwell Cloud Tech Co, Ltd 360Eyes Pro v3.9.5.16(3090516) was…6.5
- CVE-2024-28276Sourcecodester School Task Manager 1.0 is vulnerable to Cros…6.1
- CVE-2024-28277In Sourcecodester School Task Manager v1.0, a vulnerability …6.1
- CVE-2024-28279Code-projects Computer Book Store 1.0 is vulnerable to SQL I…7.3
- CVE-2024-28283There is stack-based buffer overflow vulnerability in pc_cha…6.7
- CVE-2024-28285A Fault Injection vulnerability in the SymmetricDecrypt func…9.8
- CVE-2024-28286In mz-automation libiec61850 v1.4.0, a NULL Pointer Derefere…7.5
- CVE-2024-28287A DOM-based open redirection in the returnUrl parameter of I…7.3
- CVE-2024-28288Ruijie RG-NBR700GW 10.3(4b12) router lacks cookie verificati…9.8
- CVE-2024-2829An issue has been discovered in GitLab CE/EE affecting all v…7.5
Are you affected by CVE-2024-2828?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
